IBM and Red Hat announce “Project Lightwell,” a $5 billion commitment aimed at improving the security of open-source software supply chains. Across outlets, the initiative is described as an AI-assisted effort to identify vulnerabilities, triage them, validate fixes, and support upstream maintenance, with an emphasis on scaling remediation in ways that fit enterprise software lifecycles. The project includes a “trusted enterprise clearinghouse” that coordinates security work and serves as a security layer to validate and test patches across large volumes of open-source code.
IBM and Red Hat also say they will mobilize a global workforce of more than 20,000 engineers, supported by AI capabilities, to help enterprises integrate secure patches into existing supply chains. The offerings are described as available through commercial subscriptions, with enterprise-grade validation and lifecycle management.
Initial collaboration is reported with major financial institutions, including Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo. Sources characterize early adoption as a way to guide how vulnerabilities are identified, validated, and remediated at scale. One outlet additionally ties the effort’s AI context to a separate, unreleased cybersecurity model referenced in industry coverage.