Google announces a $12.5 million pledge as a founding member of the Linux Foundation's Alpha-Omega Project to advance open source security in the AI era, alongside Amazon, Anthropic, Microsoft/GitHub, and OpenAI. The funding will help maintainers address AI-driven threats and deploy advanced security tools like Big Sleep and CodeMender.
<img src="https://storage.googleapis.com/gweb-uniblog-publish-prod/images/25367___BRS___Aspen_Security_Fo.max-600x600.format-webp_J9uPoFt.webp">Google is making new investments, building new tools and developing code security to improve open source security.
# Our latest investment in open source security for the AI era
Source: https://blog.google/innovation-and-ai/technology/safety-security/ai-powered-open-source-security/
Your browser does not support the audio element.
Listen to article
This content is generated by Google AI. Generative AI is experimental
[duration] minutes
Billions of people rely on an Internet built on open source software — which is software anyone can use — but that reliance only works if the software beneath it is secure. That’s why for over 20 years, Google has championed open source by supporting the developers who secure it — fueling initiatives like Google Summer of Code (https://summerofcode.withgoogle.com/) and bug-hunting programs (https://bughunters.google.com/) that discover and fix more vulnerabilities.
Today, as a founding member of the Linux Foundation's Alpha-Omega Project (https://alpha-omega.dev/), we’re pledging $12.5 million (https://www.linuxfoundation.org/press/linux-foundation-announces-12.5-million-in-grant-funding-from-leading-organizations-to-advance-open-source-security) collectively with Amazon, Anthropic, Microsoft/GitHub and OpenAI to further invest in the stability and security of the open source community. The funding, managed by Alpha-Omega and OpenSSF, will help maintainers stay ahead of a new generation of AI-driven threats, move security beyond vulnerability discovery to actually deploying fixes, and put advanced security tools directly into maintainers’ hands, to turn a flood of AI-generated findings into fast action.
In addition to its industry-wide commitments, Google is dedicated to helping the open source community to outpace evolving threats and tip the scales in favor of the defenders (https://blog.google/innovation-and-ai/technology/safety-security/google-ai-cyber-defense-initiative/) by providing advanced AI tools for wider use.
Internally, Big Sleep (https://projectzero.google/2024/10/from-naptime-to-big-sleep.html) and CodeMender (https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/), both AI-powered tools from Google DeepMind, have already shown incredible success in helping us protect our own systems, demonstrating that AI can autonomously find and fix deep, exploitable vulnerabilities in systems as complex as the Chrome browser. We’re also extending research initiatives like Sec-Gemini (https://secgemini.google/) to open source projects (interest form (https://docs.google.com/forms/d/e/1FAIpQLSer19zNknZiZybByZTo2SmyMu9vLK_ViOodTU8rAIJy-wkQtQ/viewform?usp=publish-editor)). These breakthroughs show the transformational potential of AI to secure the wider open source ecosystem.
Open source is the backbone of the modern web, and we’re proud to support the maintainers who secure it to move faster, stay safer and continue building the future.
## Get more stories from Google in your inbox.
Done. Just one step more.
Check your inbox to confirm your subscription.
You are already subscribed to our newsletter.
You can also subscribe with a
Industry leaders including NVIDIA, Microsoft, and the Linux Foundation launch the Open Secure AI Alliance to promote open-source AI tools and models for cybersecurity defense.
GitHub's Secure Open Source Fund's fourth session invested $500,000 across 50 open source projects to improve security using AI-assisted workflows, GitHub security tools, and expert guidance, highlighting the continued role of maintainers.
The week-old Open Secure AI Alliance (OSAA), led by Nvidia and now including over 120 companies, is already presenting proposals for AI security and collecting open-source contributions from members like Amazon, Red Hat, and Okta, while notable firms such as OpenAI and Google have not yet joined.
Google commits $40 million in AI tokens and cloud credits to support the US Department of Energy's Genesis Mission, providing frontier AI tools like AlphaEvolve and AlphaFold 3 to accelerate scientific discovery across national laboratories.
OpenAI announces $110B in new investment at a $730B pre-money valuation, including major funding from SoftBank, NVIDIA, and Amazon, along with strategic partnerships to expand compute capacity and global reach for AI products. The funding aims to accelerate deployment of frontier AI across consumers, developers, and enterprises worldwide.