OpenAI discloses its coordinated vulnerability disclosure approach
The policy left disclosure timelines open-ended by default, reflecting that OpenAI's own systems were already finding zero-day flaws in third-party open-source software.
- Security & misuse
- Colour
OpenAI published an outbound coordinated vulnerability disclosure policy, setting out how it will report security flaws its own research and AI tools discover in third-party and open-source software. The company said its systems had already uncovered zero-day vulnerabilities in software it relies on, and that it expected AI tools to become increasingly capable of finding — and helping to patch — such flaws going forward, making a formal disclosure process necessary before that capability scaled further.
The policy covers vulnerabilities found through OpenAI’s own research, targeted audits of open-source code the company depends on, and automated analysis using its AI tools. Notably, it left disclosure timelines open-ended by default rather than committing to the fixed windows (commonly 90 days) used by many security researchers and firms, which OpenAI framed as a deliberately developer-friendly stance reflecting how unsettled the practice of AI-assisted vulnerability discovery still was.
The announcement sat alongside an existing bug bounty programme, under which OpenAI said it had paid out for hundreds of reported vulnerabilities in its own products since the programme’s 2023 launch. Taken together, the policy positioned OpenAI as both a target of security research and, increasingly, a source of it — an acknowledgement that frontier models were becoming tools capable of automated vulnerability discovery at a scale that outpaced existing disclosure norms.