OpenAI launched the "Patch the Planet" initiative on Monday, June 22, 2026, in partnership with the security company Trail of Bits. The initiative offers free security consulting and AI-powered tools to open source maintainers to assist in patching software vulnerabilities.
Trail of Bits security staff will work directly with open source maintainers to review potential code issues. OpenAI's Codex Security tools will be used to assist in this process, and the company has already subsidized usage of its Codex Security scanner for open source and private code totaling 20 trillion tokens. In connection with the initiative, OpenAI released its Codex Security scanner as an app plugin, announced an improved version of its limited-access security-specialized model GPT-5.5-Cyber, and expanded international work with governments and other institutions to provide "trusted access" to its latest cybersecurity-focused models.
More than 30 open source projects are participating in Patch the Planet. Trail of Bits conducted a five-day opening sprint with 25 engineers working on collaborations with maintainers. OpenAI and Trail of Bits stated the project uncovered hundreds of bugs and produced dozens of patches in its first week. The initiative also collaborates with vulnerability management firms HackerOne and Calif.
Dan Guido, CEO and cofounder of Trail of Bits, said, "Patch the Planet is an internet-scale effort to help open source software get ahead of AI bug hunting tools." He added, "But it's also an effort to help the open source community see the benefits and not just the downsides of AI coding tools." Guido also said, "It's so rare that we get the opportunity to work on large scale open source security issues," and noted, "And Patch the Planet is not a one size fits all."
OpenAI said, "Many maintainers are already being asked to sort through more reports, more quickly, with the same limited time and resources." The company stated, "Patch the Planet is built to reduce that burden, not add to it: security engineers review findings before they reach maintainers, work with projects to develop patches and tests, and build reusable workflows that help teams continue improving security after the first fixes land."
OpenAI cyber tech lead Fouad Matin said, "Maintainers do their work out of love of open source and now they're stuck reviewing slop CVEs." Matin added, "We want to offset costs, whether it's tokens or people power, to actually patch as much of the world of software as possible." He said, "What we've effectively done is make it as efficient from a token perspective as possible to reduce the burden for maintainers—code base assessments, validating potential reports, creating patches, and landing them."
forum Comments (0)
No comments yet. Be the first to comment.