OpenAI on Monday announced a suite of cybersecurity-focused initiatives, led by a new project called Patch the Planet, aimed at helping open source software projects fix vulnerabilities and adopt AI-driven security tools. The effort is founded with the prominent research-focused security firm Trail of Bits and in collaboration with vulnerability management firms HackerOne and Calif, according to WIRED.
What Is Patch the Planet?
Patch the Planet is described by Trail of Bits CEO and cofounder Dan Guido as "an internet-scale effort to help open source software get ahead of AI bug hunting tools." The project offers free security consulting services to open source maintainers, not only to find and patch vulnerabilities but also to strengthen codebases and incorporate AI security tools into their development process. The goal is to provide individualized support to as many open source projects as possible in a sustainable way.
OpenAI's cyber tech lead Fouad Matin explained that the company has made the effort "as efficient from a token perspective as possible to reduce the burden for maintainers—code base assessments, validating potential reports, creating patches, and landing them." He added, "We want to offset costs, whether it's tokens or people power, to actually patch as much of the world of software as possible."
The Burden on Open Source Maintainers
Open source developers—often volunteers maintaining critical software with limited resources—are already struggling with bug reports. The rise of AI vulnerability hunting has made the backlog feel insurmountable as AI-generated slop reports stack up, pulling time and attention away from critical flaws. Matin noted that maintainers "do their work out of love of open source and now they’re stuck reviewing slop CVEs." Patch the Planet aims to alleviate that by providing direct support.
Early Results
More than 30 open source projects are already participating in Patch the Planet, with more in the pipeline. To launch the project, Trail of Bits recently conducted a five-day opening sprint with 25 engineers—roughly a fifth of its workforce—working simultaneously on collaborations with maintainers. According to OpenAI and Trail of Bits, the project has already uncovered hundreds of bugs and produced dozens of patches in its first week. Guido said that with funding from OpenAI and unmetered model access, Trail of Bits plans to continue its intense commitment long term, tailoring support to each project's highest priorities, such as building better testing infrastructure or custom fuzzers.
Broader Cybersecurity Announcements
Alongside Patch the Planet, OpenAI announced an improved version of its limited-access security-specialized model GPT-5.5-Cyber, expanded international work with governments and institutions to give them "trusted access" to the company's latest cybersecurity-focused models, and released its Codex Security scanner as an app plugin. Matin added that for Codex Security scanner, which has been in research preview since earlier this year, OpenAI has been subsidizing usage for both open source and private code "to the tune of 20 trillion tokens."
Competitive Context
The announcements come as OpenAI's competitor Anthropic had to pull its new Fable 5 and Mythos 5 models off the market earlier this month amid fear from the Trump administration, according to WIRED. The full details of that development were not provided in the source, but it underscores the intensifying competition in AI cybersecurity.
For enterprise technology leaders, the security of open source software is a critical concern as it underpins much of the digital infrastructure. Patch the Planet's approach of combining human expertise with AI tools could set a new standard for vulnerability management, potentially reducing the risk of breaches that impact supply chains and logistics systems.