RE: https://shkspr.mobi/blog/2026/05/gds-weighs-in-on-the-nhss-decision-to-retreat-from-open-source/
AI, open code and vulnerability risk in the public sector - GOV.UK
https://www.gov.uk/guidance/ai-open-code-and-vulnerability-risk-in-the-public-sector
Guidance for safely publishing source code in the open, and reducing the risk of AI-accelerated vulnerability discovery.
"Technology leaders are asking whether AI-accelerated vulnerability discovery means that public sector departments should stop publishing source code ‘in the open’ by default.
User research suggests that the primary driver of exploitation risk is the presence of weaknesses in systems - including unpatched vulnerabilities, insecure implementation, and unsafe configuration or deployment - and the inability to remediate them quickly. Publishing source code does not create those weaknesses, but it can modestly reduce attacker uncertainty and speed up analysis (an effect that may increase with AI assistance), especially where maintenance is weak and fixes are slow. This guidance reinforces the minimum operational capability already assumed for safely operating publicly-accessible services. …"
#AI #security #vulnerability #discovery #defence #cybersecurity #opensource #LLM #Anthropic #Claude #Mythos #NCST #DSIT #government