OpenAI Publishes Policy for Disclosing Bugs It Finds in Others' Software
OpenAI has published rules for reporting vulnerabilities its AI systems find in third-party software, after its models already uncovered zero-days. Timelines stay open-ended by default.

Updated
Why it matters
- OpenAI published an Outbound Coordinated Disclosure Policy covering how it reports security issues found in third-party and open-source software via automated and manual code review.
- OpenAI says its systems have already uncovered zero-day vulnerabilities in third-party and open-source software.
- The policy leaves disclosure timelines open-ended by default, while reserving the right to disclose when there is public interest in doing so.
OpenAI has published an Outbound Coordinated Disclosure Policy governing how it reports security vulnerabilities its systems discover in third-party and open-source software — and it says its models have already uncovered zero-day vulnerabilities in code it does not own.
The policy, released on OpenAI's website, applies to findings from automated and manual code review, targeted audits of open-source code OpenAI uses, and vulnerabilities surfaced through internal use of third-party software and systems. It covers both open-source and commercial software.
The move signals a shift in the security landscape. As AI systems grow more capable of finding and patching vulnerabilities, the volume of outbound disclosures from AI developers is likely to grow with them. OpenAI frames the policy as a proactive step in anticipation of that future rather than a reaction to a single incident.
What the policy actually says
The document spells out four things: how OpenAI validates and prioritizes findings, how it contacts vendors and the mechanics it follows, when and how it goes public, and the principles behind the process. Those principles include being impact-oriented, cooperative, discreet by default, operating at high scale with low friction, and providing attribution to researchers when relevant.
On publication, the default is non-public disclosure first — details stay private with the affected vendor unless circumstances demand otherwise.
The most consequential design choice is timing. OpenAI has deliberately left disclosure timelines open-ended by default.
"We take an intentionally developer-friendly stance on disclosure timelines and have elected to leave timelines open-ended by default," the company states.
The rationale ties directly to AI capability. As models get better at reasoning about code, its strengths and weaknesses, and generating reliable patches, OpenAI expects them to detect a growing number of bugs of increasing complexity — bugs that may require deeper collaboration and more time to resolve sustainably.
The company does retain an escape hatch: "We still reserve the right to disclose when we determine there is, for example, public interest in doing so."
Why it matters
Coordinated vulnerability disclosure has long been governed by an evolving set of norms among researchers, vendors, and maintainers — often without hard rules. Google's Project Zero, for instance, has enforced a strict 90-day disclosure deadline since 2014, a policy that has repeatedly forced vendors to ship patches on a fixed clock. OpenAI's choice to leave timelines open by default breaks with that precedent and could set a different tone as AI-generated findings start arriving at scale.
That scale is the core of the story. Traditional security research produces a trickle of findings from human analysts. AI systems running continuous automated analysis over codebases could produce a flood, and many of those findings will land with volunteer maintainers of open-source projects who have limited time and no patching budget. OpenAI says it will "continue working with software maintainers to develop disclosure norms that balance urgency with long-term resilience" — an acknowledgment that current norms may not survive contact with AI-driven discovery volumes.
The zero-day claim is also notable on its own. OpenAI states that "systems developed by OpenAI have already uncovered zero-day vulnerabilities in third-party and open-source software." The company does not name the affected software or the systems involved, but the statement positions AI-driven vulnerability discovery as a present capability, not a projection.
The policy frames OpenAI's motivation in ecosystem terms: "We are committed to advancing a secure digital ecosystem."
Mechanics and contact
The policy document explains how findings get validated and prioritized before any vendor contact, and it commits OpenAI to disclosure mechanics that are cooperative and discreet. Vulnerabilities reach OpenAI through three routes, per the announcement: ongoing research, targeted audits of open-source code the company leverages, and automated analysis using AI tools.
OpenAI has set up a dedicated channel for questions about its disclosure practices: [email protected].
The company describes the policy as a living document. "We will keep improving this policy as we learn," the post reads, adding that transparent communication about the approach is meant to support "a healthier, more secure ecosystem for everyone."
The road ahead
For maintainers of widely used open-source projects, the policy raises a practical question: what happens when an AI system reports dozens of complex vulnerabilities at once, with no fixed deadline attached? OpenAI's bet is that open-ended timelines and cooperative defaults will produce better long-term security outcomes than rigid deadlines. Whether the rest of the security community agrees — and whether other AI developers adopt similar outbound policies — will shape how vulnerability disclosure works in an era when finding bugs is no longer the bottleneck.
Source: OpenAI News
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
121 articles
Related articles
- OpenAI models broke out of isolation and breached Hugging Face
- OpenAI Launches Safety Bug Bounty to Pay for AI Abuse Findings
- OpenAI details how it runs Codex safely in production
- OpenAI launches misalignment disclosure framework, publishes six reports
- OpenAI and Paradigm Launch EVMbench for Smart Contract Security