Open source security is reaching a breaking point, and artificial intelligence sits at the center of both the problem and the solution. Jamie Thomas, IBM's Chief Client Innovation Officer for Enterprise Security, told attendees at the Linux Foundation Open Source Summit that vulnerability disclosures are climbing at a record pace. Roughly 66,000 unique entries are expected in 2026 alone, a fourfold increase from seven years ago.
The Exploitation Window Is Shrinking
Cybercriminals are exploiting vulnerabilities in as little as 29 minutes, according to Thomas. In some cases, attacks begin before a patch exists. The time to exploit has become negative, she said, meaning disclosures often arrive with no fix ready. This leaves defenders with almost no room to respond.
AI-Generated Reports Swamp Maintainers
The volume of low-quality reports has become unmanageable. The developers of curl terminated their bug bounty program, citing AI-generated submissions that were poorly researched or entirely fake. Google paused its Open Source Software Vulnerability Rewards Program after a significant rise in invalid reports. Linus Torvalds said AI bug hunters have made the Linux security mailing list almost entirely unmanageable, with the same findings reported over and over.
Large companies with dedicated security teams struggle to keep up. Many open source projects, on the other hand, are maintained by small groups or even a single developer. The burden falls heaviest on those with the fewest resources.
IBM and OpenSSF Push AI as a Filter
Thomas argued that the security community should not abandon AI-driven discovery but instead use the same technology to manage the workload. The Open Source Security Foundation, backed by IBM, is exploring ways to apply machine learning to the deluge of reports. According to Thomas, AI tools could help in several ways:
This approach could reduce the strain on maintainers while preserving the benefits of automated discovery. The goal is to make AI a defensive ally rather than an annoyance generator.
Why This Matters
The sustainability of open source hangs in the balance. If maintainers walk away or projects collapse under the load, the entire software ecosystem faces cascading failures. Attackers are already using automation to speed up their operations, and the defensive side is falling behind. The race to deploy AI defensively will determine whether open source remains a trusted foundation for modern technology. Without effective triage, the growing number of vulnerabilities will outpace the human ability to address them, leaving critical systems exposed.



