Akrites
A Linux Foundation-hosted industry body for coordinated vulnerability discovery, remediation, and disclosure of critical open-source software (akrites.org), launched June 2026 by ~20 founding organizations — AWS, Anthropic, Google, Microsoft and its GitHub subsidiary, OpenAI, Cisco, Red Hat, NVIDIA, Chainguard, Sonatype, Ericsson, Vodafone, Citi, and JPMorganChase among them. It was created specifically to answer AI-enabled cyber threats: frontier models can now scan a major open-source project and surface many vulnerabilities in a single pass — a tool defenders and attackers both hold. The name comes from the Akritai, the soldiers who guarded the Byzantine Empire’s most exposed borders (akrites-launch-tns).
Why it sits in this wiki — a governance modality, not a tool
Akrites is industry collective self-governance: a multi-firm, non-state body that governs AI-related security risk by coordinating defense rather than by setting conduct rules or gatekeeping distribution. It extends the spoke’s “instruments beyond conduct rules” map with a lever none of the prior sources had — neither a state writing law nor a standards body writing protocol, but competitors pooling vulnerability-response under a neutral foundation.
How it works — the shared SIRT
The core is a shared Security Incident Response Team (SIRT) acting as a single industry coordination point. Instead of a maintainer receiving a dozen duplicate reports of the same flaw from a dozen firms, the SIRT consolidates findings, validates which are genuinely exploitable, and runs one coordinated fix-and-disclosure process under strict confidentiality, using established standards (CVE, CVSS). Patches return to the project on the maintainer’s terms; for unmaintained projects, Akrites steps in as a fallback so a fix still ships. The problem it targets is duplication itself: every extra party holding an unpatched-vuln secret raises the odds it leaks before a fix exists.
Structure & funding
- Membership, three tiers — Premier (critical-infrastructure operators + their vendors), General (contribute without large engineering commitment), Associate (open-source foundations and projects, free).
- Seed funding — from Alpha-Omega, an OpenSSF project (Anthropic, AWS, Google, Microsoft, OpenAI backers), annual budget >$7M. Microsoft’s Azure CTO Mark Russinovich frames Akrites as building on the OpenSSF/Alpha-Omega precedent for “the emerging inflection point of AI-powered vulnerability discovery and defense.”
The governance argument it makes
The Anthropic framing (Jason Clinton, deputy CISO) is that coordinated disclosure has been outpaced by how fast AI now finds vulnerabilities, so the fix must “get upstream before they’re disclosed and exploited.” Endor Labs’ Varun Badhwar adds the asymmetry the body is built around: discovery was never the hard part — fixing is — and AI has made that gap “impossible to ignore” (his firm cites thousands of AI-found OSS vulns with <5% patched, an unverified figure).
Related
akrites-launch-tns · linux-foundation · anthropic-export-ban-2026 · cyber-export-control-history · export-controls-on-ai · ietf · ai-governance · synthesis