Discovery Is Outrunning Remediation Everywhere. That Is Not Just a Technology Problem.
A model found 1,596 unpatched vulnerabilities in open source projects last month. The industry’s answer was more infrastructure for finding problems. That was never the part that was broken.
Anthropic, Google, OpenAI, Microsoft, and more than a dozen other organizations just did something companies rarely do voluntarily. They pooled money into a shared body, called Akrites and hosted by the Linux Foundation, because none of them could keep pace with open source vulnerability discovery and remediation on their own.
Organizations build shared infrastructure at this speed for one reason. A risk got too expensive for any single balance sheet to absorb quietly. That is what a captive insurance pool is. A group of companies decides a risk is real and common enough that carrying it alone costs more than carrying it together. Nobody calls that admission a taskforce. They call it underwriting, and they usually get a board resolution and a name plate before anyone says the real reason it exists out loud.
The gap that triggered this is specific and measurable, not theoretical. A single model surfaced 1,596 verified vulnerabilities across hundreds of open source projects. Most had no visible fix attached, according to Tuskira’s analysis, reported by Help Net Security. Discovery is outrunning remediation everywhere, not only inside the handful of companies with the balance sheet to fund a Linux Foundation initiative about it.
Here is the part that belongs on your desk and not only your CISO’s. You did not get a vote on whether your organization joined Akrites. You are covered by what it finds whether you contributed to its formation or not, in the same way every company benefits from a standard it did not help write. That is not a complaint. It is a description of where the accountability actually sits now. The industry just built the discovery function. The decision about what your organization does with what that function surfaces still belongs to exactly one desk inside your walls, and right now that desk is empty.
Two clocks are already running underneath this. SEC disclosure rules put personal accountability on the executive who signs off on a security posture with no documentation behind it. The EU Cyber Resilience Act adds a second one. Manufacturers must send an early warning on an actively exploited vulnerability to ENISA within 24 hours of becoming aware of it, starting September 11, 2026, for products already on the market. Neither clock is waiting for Akrites to finish its first year.
None of this requires your organization to solve AI driven vulnerability discovery on its own. Funding a shared body was the whole point of not solving it alone. The technology problem, discovery outrunning remediation, just got an industry scale answer. What no coordination effort can do on your behalf is make the one decision that was always going to sit inside your organization: how much of the exposure that body surfaces is acceptable to carry, who weighed that call, and on what evidence.
That decision has to leave a mark somewhere, or it does not count. Not a scan result. Not a line in a risk register with no name attached to it. A documented call: this exposure was identified, this person or committee weighed it against the alternative, and this was the decision, made on this date, with this evidence on the table. That is the artifact a regulator, an auditor, or a plaintiff’s attorney asks for after something goes wrong. Most organizations only find out they never created one at the exact moment they need it most.
A CFO and a CISO are asking a version of the same question in different vocabulary. Not whether open source vulnerabilities exist. Every company has them, and now an industry body exists to confirm the scale. The question is whether anyone inside your organization can produce, today, the name attached to the decision about how much of that exposure you chose to carry.
Most cannot answer that yet. That is not evidence the security team is behind. It is evidence the decision was never assigned to a person in the first place, and that gap is far cheaper to close before an incident than to explain after one.

.png)
.png)
Comments
Post a Comment