SAN FRANCISCO — The program’s name borrows from a line in the 1995 film “Hackers,” in which a teenager declares an ambition to “hack the planet.” OpenAI’s version, called Patch the Planet, launched Monday with a different ambition: to help the people who maintain open-source software find and fix the vulnerabilities that make the modern internet fragile. The company is working with Trail of Bits, a security firm whose engineers will work directly with project maintainers.
The arrangement is concrete in ways that corporate security initiatives often are not. Trail of Bits engineers will be assigned to open-source projects, where they will review code for vulnerabilities and work with maintainers on fixes, according to OpenAI’s announcement. The effort will draw on OpenAI’s Codex tools, which can analyze code and suggest changes, and the company said the security model being released alongside the program, GPT-5.5-Cyber, is designed specifically for defensive security work.
The choice of Trail of Bits is telling. The firm has built its reputation on the kind of work that most companies avoid: deep audits of code that other engineers consider too difficult or too dangerous to touch. Its clients have included the U.S. government and major technology companies, and its engineers are known for finding vulnerabilities in systems that were assumed to be secure. Giving that team to open-source maintainers is a transfer of capability that the maintainers could not otherwise afford.
The problem the program addresses has been visible for years. Open-source software is the foundation of the digital economy, but its security is financed by volunteers and donations. The maintainers of libraries used by millions of applications are often unpaid, and the vulnerabilities in their code are found by attackers as often as by defenders. The log4j vulnerability of 2021, which allowed remote code execution on millions of servers, was fixed by a small team of volunteers working around the clock.
The economics of the program matter as much as the technology. OpenAI has not disclosed the budget, but the deployment of Trail of Bits engineers and the release of a specialized security model represent a real investment in an area where the industry has historically spent little. The bug bounty program that accompanies the launch gives independent researchers a financial incentive to join the effort, and the combination is designed to produce a pipeline of vulnerabilities found and fixed.
The timing connects to a broader moment in AI security. Researchers have shown that large language models can identify vulnerabilities in code faster than traditional scanning tools, and that the same capability can be turned to defense or offense. OpenAI’s program is a bet that AI-assisted security work can shift the balance toward defenders, provided the discoveries are shared with the people who can fix them.
The partnership model is the program’s most distinctive feature. Rather than publishing vulnerability reports in the open and letting maintainers scramble to respond, Trail of Bits engineers will coordinate with project maintainers directly, working through fixes before any disclosure. The approach avoids the adversarial dynamic that has poisoned relationships between security researchers and maintainers, and it matches the way the best-funded security teams already operate.
The program has limits that its creators acknowledge. A handful of engineers and a security model cannot secure the entire open-source ecosystem, which includes millions of projects of varying quality and maintenance status. The program will have to choose where to focus, and the choices will determine its impact. OpenAI has said it will prioritize projects based on their importance to the broader software ecosystem, and the list will be published as the program proceeds.
The competitive context is unavoidable. Anthropic has positioned itself around safety, publishing its Mythos security framework and courting enterprise customers with promises of responsible AI, and OpenAI’s security push is widely read as a response. The two companies are now competing on security standards the way they compete on model benchmarks, and the winner of that competition will shape how governments and enterprises evaluate AI providers.
The program’s success will be measured in mundane terms: vulnerabilities found, patches shipped and projects that are stronger than they were. OpenAI has said it will publish progress updates, including the list of projects being reviewed, and the company has committed to working with the maintainers rather than around them, an approach that the open-source community has learned to appreciate after years of researchers publishing flaws without offering fixes. The most valuable outcome, maintainers said, would be a model for how AI companies contribute to the commons they depend on, one that other labs can copy without reinventing the rules of engagement. The program’s real test will come in a year, when the first wave of reviews is complete and the community can see whether the vulnerabilities were found, the patches were shipped and the promise was kept.
For the maintainers on the receiving end, the program is a change in fortune. The volunteers who keep the internet running have spent years asking for help, and professional security review is the help they most need. Whether the attention lasts beyond the current cycle of corporate competition will determine whether Patch the Planet leaves open-source security durably stronger or fades as a well-funded gesture.


