All
Company
Alex Panait
Chief Executive Officer

Cyber Defense Needs a Commons Beneath the Coalition

The institutions mobilizing against AI-enabled cyber threats need an open, durable layer that allows defensive knowledge to spread across the entire software ecosystem.

September 2, 2026
7 MIN READ
Interested in learning more? Contact our team today

Greg Brockman is right: we have a limited window to strengthen global cyber defenses, and the status quo will not be enough.

OpenAI's call for collective action correctly recognizes that this cannot be solved by any one company or government. Enterprises, cybersecurity companies, public institutions, frontier AI labs, researchers, and maintainers all have roles to play. Organizations with resources, reach, and advanced capabilities should move quickly—and should help defenders who lack those advantages. (https://openai.com/lv-LV/collective-cyberdefense/)

But institutional coordination is only part of the answer.

Cyber defense in the AI era needs both a coalition and a commons.

A coalition concentrates resources, coordinates major institutions, and mobilizes action around urgent priorities. A commons allows discoveries, fixes, tools, and practical knowledge to spread beyond the organizations that produced them.

A coalition coordinates organizations. A commons compounds contributions.

The strongest defense will combine both.

The missing variable is propagation

Defenders already share information. The problem is that they often share too slowly, through fragmented systems that do not reliably reach one another.

A dangerous vulnerability may be discovered in one project while thousands of other projects carry a related weakness. A maintainer may develop an effective mitigation that never reaches another team confronting the same problem. A researcher may identify a recurring vulnerability class, but the lesson remains trapped in a report rather than becoming a reusable test, rule, patch pattern, or hardened component.

The intelligence exists. The propagation does not.

Attackers can reuse techniques across targets with extraordinary speed. Defensive knowledge must become equally portable.

A vulnerability discovered in one place should become a lesson available elsewhere as quickly as safety permits. A verified patch should become a searchable pattern across an ecosystem. A defensive technique developed by one team should become reusable infrastructure for thousands of others.

Sharing between organizations is essential. But sharing that can propagate without requiring a new partnership, procurement process, or access decision for every beneficiary is more powerful.

That is the role of a defensive commons.

Open source is part of the world’s critical infrastructure

Much of the digital world depends on software maintained by small teams and individual contributors: operating systems, cryptographic libraries, networking tools, language runtimes, package ecosystems, and dependencies embedded inside countless commercial and public systems.

Most of these projects cannot support a dedicated security organization.

Yet the security of governments, hospitals, businesses, utilities, and individual users often depends on their work.

The imbalance is increasingly untenable: a small and underfunded team may maintain software used by millions of people while facing adversaries equipped with rapidly improving automation.

AI can help change that equation. It can assist with code review, dependency analysis, vulnerability discovery, exploitability assessment, remediation, testing, and coordinated disclosure. OpenAI has already demonstrated serious interest in this problem through initiatives supporting open-source projects and maintainers. The next step is to make the resulting defensive capacity more durable, interoperable, and broadly reusable. (https://openai.com/index/scaling-trusted-access-for-cyber-defense/)

Open-source maintainers should not be treated only as recipients of assistance. They are themselves a distributed defense layer.

Where the coalition can go further

Trusted-access programs are a necessary response to the dual-use nature of advanced cyber capabilities. More capable models can help defenders identify and remediate vulnerabilities, but those same capabilities can also be misused.

The answer cannot be indiscriminate release.

At the same time, a system built entirely around centralized access decisions has structural limits. The reach and speed of defense become partly dependent on who has been approved, which tools they may use, where those tools can operate, and whether the relevant provider remains available.

Resilience requires redundancy.

No single company, model provider, government, or security vendor will see every vulnerability. Independent researchers, academics, maintainers, enterprises, and public institutions will notice different things because they occupy different parts of the ecosystem.

We should build that diversity into the defense model deliberately:

- trusted access to the most sensitive capabilities;

- open defensive tooling wherever responsible release permits;

- support for multiple models and deployment environments;

- shared evaluation methods;

- funding for open-source security infrastructure;

- independent verification of defensive claims;

- and rapid dissemination of validated fixes.

The objective is not to eliminate gates where gates are necessary. It is to ensure that the entire defensive ecosystem does not depend on one gatekeeper.

Openness must be governed

A defensive commons cannot mean publishing every capability or vulnerability immediately.

A system capable of finding serious vulnerabilities at scale could accelerate attacks if findings or methods are released recklessly. Responsible openness therefore requires more infrastructure, not fewer controls:

- authorized testing and defined scope;

- private reporting to affected maintainers;

- coordinated disclosure procedures;

- embargo periods where necessary;

- risk-tiered access to sensitive capabilities;

- reproducible validation before a finding is accepted;

- and broad distribution of defensive knowledge after a fix is available.

The distinction should be between open infrastructure and uncontrolled disclosure.

We can build tools and workflows that are inspectable, independently testable, and portable while still protecting sensitive findings and limiting dangerous actions.

That is a harder model to build than either total openness or total centralization. It is also more durable.

What the defensive commons should contain

The commons should be practical infrastructure, not merely another forum or declaration.

It should support:

1. Vulnerability discovery

Finding recurring vulnerability classes across projects and ecosystems—not only inside individual organizations.

2. Responsible disclosure

Giving maintainers safe, predictable channels to receive, reproduce, prioritize, and resolve findings.

3. Verified remediation

Testing whether a patch closes the vulnerability without breaking expected behavior or introducing a new weakness.

4. Defensive intelligence

Turning discoveries into machine-readable rules, signatures, tests, mitigations, and hardened patterns.

5. Open defensive tooling

Providing scanners, analyzers, evaluation suites, and reusable components that maintainers can deploy without a lengthy procurement process.

6. Shared security memory

Preserving the relationship between vulnerabilities, root causes, failed fixes, successful remediations, and regression tests so that the ecosystem does not repeatedly rediscover the same lesson.

7. Independent verification

Allowing qualified outside researchers to test whether security claims and proposed remediations actually hold.

None of this replaces the institutional response Brockman is calling for. It is the infrastructure underneath it—the layer capable of reaching projects too small, distributed, or underfunded to participate in every formal program.

ClearWing as one contribution

This is the direction we are pursuing with ClearWing, an open-source security-research project designed to help make AI-assisted defensive work more inspectable, reproducible, and reusable.

ClearWing is not a substitute for frontier models, professional security teams, disclosure organizations, or institutional coordination. It is intended to help connect them: supporting governed research workflows across supported models and environments while preserving evidence that others can review and reproduce.

The public project should remain independently useful. Commercial work can fund the support, integrations, hardening, and governed deployment that larger organizations require, but it should also contribute improvements back to the shared defensive foundation wherever security and disclosure constraints permit.

We offer ClearWing not as the completed commons, but as one practical building block—and an invitation to researchers, maintainers, security teams, model providers, funders, and public institutions to help shape what this infrastructure should become.

Sustainability is security

A commons is not sustainable if it depends on exhaustion and goodwill.

Maintainers cannot protect critical infrastructure indefinitely without funding, technical support, and time. Security work competes with features, releases, documentation, user support, and every other demand placed on an open-source project.

Companies and governments that depend on open-source software should fund its defense—not as charity, but as basic risk management.

That means direct support for critical projects, paid security work, remediation assistance, better disclosure infrastructure, and compensation for the time maintainers spend responding to vulnerabilities.

Open source is not a free resource to be extracted. It is shared infrastructure, and shared infrastructure requires maintenance.

Measure whether defense is actually improving

The success of this effort should not be measured by the number of announcements, conferences, or partnerships it produces.

It should be measured by whether attacking the ecosystem becomes harder.

Useful measures include:

- time from discovery to validated remediation;

- vulnerabilities eliminated rather than merely reported;

- downstream projects protected by a single verified fix;

- recurrence rates for previously understood vulnerability classes;

- time required for defensive intelligence to propagate;

- the percentage of findings reproduced independently;

- and the number of maintainers gaining defensive capabilities they did not previously possess.

The central question is simple:

Are we converting isolated discoveries into protection that compounds across the ecosystem?

Both, not instead

A coalition and a commons are not competing proposals.

Institutions have resources, mandates, and the ability to move large organizations. Governments can fund public defense and protect critical infrastructure. Frontier labs can give qualified defenders access to extraordinary capabilities. Security companies can operationalize those capabilities at scale.

A commons adds reach, redundancy, portability, and memory. It protects parts of the internet that no formal program will ever fully cover.

Let institutions mobilize.

Let governments fund defense.

Let frontier labs put their most capable technologies to work protecting essential systems.

And let maintainers, hackers, researchers, independent developers, and security teams build the shared infrastructure underneath that mobilization.

Attackers can discover a vulnerability once and exploit it across thousands of systems.

Our objective should be the inverse: discover the weakness once, verify the fix, turn the lesson into shared infrastructure, and propagate protection faster than the attack can spread.

That is the defensive asymmetry worth building—together.

-Alex

ClearWing repository:

https://github.com/Lazarus-AI/clearwing

Contribution guide:

https://github.com/Lazarus-AI/clearwing/blob/main/CONTRIBUTING.md

Security and disclosure policy:

https://github.com/Lazarus-AI/clearwing/blob/main/SECURITY.md