Big tech is clamping down on open source ‘AI slop’ reports
Firms including Microsoft, OpenAI, and Google have pledged funding to bolster open source security and cut down on slop reports
A host of big tech firms have handed over $12.5 million in funding to advance open source security and try to eliminate "AI slop" bug reports.
Firms including OpenAI, Anthropic, AWS, Google, Microsoft, and GitHub have pledged funding for Alpha-Omega and the Open Source Security Foundation (OpenSSF), both security initiatives within the Linux Foundation.
The aim is to develop long-term, sustainable security solutions that support open source communities worldwide.
The move comes as open source maintainers contend with an unprecedented number of security reports, many of which are generated by automated systems.
Mark Ryland, director of the Office of the CISO for AWS, said these AI-generated reports are overwhelming their ability to review them.
"Many of the reports are of very low quality — a reality given rise to the new industry term 'AI slop'," he said. "Many projects have already elected to put guidelines in place for AI submissions, while others have shut down upstream contributions entirely to prevent a flood of AI-generated pull requests."
Closer ties with open source maintainers
The new investment will allow Alpha-Omega and OpenSSF to work directly with maintainers and their communities to make emerging security capabilities accessible, practical, and aligned with existing project workflows.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“Grant funding alone is not going to help solve the problem that AI tools are causing today on open source security teams,” said Greg Kroah-Hartman of the Linux kernel project.
“OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving.”
The GitHub Secure Open Source Fund is adding an additional $5.5 million in Azure credits and funding to provide training and expertise.
GitHub Security Lab, meanwhile, is improving the security advisory experience on GitHub and Private Vulnerability Reporting (PVR) features, with an eye on reducing the burden of low-quality reports and helping maintainers manage increased volume.
Google, meanwhile, will provide AI-powered tools like Big Sleep and CodeMender from Google DeepMind – already used to protect the company's own systems. It's also extending research initiatives like Sec-Gemini to open source projects.
“Our commitment remains focused: to sustainably secure the entire lifecycle of open source software,” said Steve Fernandez, general manager of OpenSSF.
“By directly empowering the maintainers, we have an extraordinary opportunity to ensure that those at the front lines of software security have the tools and standards to take preventative measures to stay ahead of issues and build a more resilient ecosystem for everyone.”
AI slop reports are skyrocketing
Concerns about AI slop bug reports have been voiced by a number of organizations, including the Python Software Foundation.
Developers behind cURL, an open source command line interface (CLI) tool which allows developers to transfer data, recently shut down its bug bounty scheme in response to a growing number of slop reports.
As ITPro reported at the time, lead maintainer Daniel Stenberg said the current volume of submissions is placing a “high load” on the security team.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Satya Nadella woos Windows users with OS improvement pledges: 'We are focused on fundamentals, prioritizing quality, and serving our core users better'News Satya Nadella told analysts that Microsoft is doing “foundational work to win back fans” across Windows, Xbox, Bing, and Edge
-
Microsoft pats itself on the back over European commitmentsNews The company says it's been working to boost the bloc's digital sovereignty and resilience
-
Everything you need to know about the GitHub Copilot pricing changesNews GitHub Copilot pricing changes mean users will be charged based on consumption, rather than a set number of credits
-
Microsoft touts “cost effective” cloud PC prices for small businesses as hardware prices spikeNews The tech giant is targeting small business gains with a 20% cut for Windows 365 Cloud PC services
-
IT admins are scrambling for alternatives in the wake of Microsoft’s MDT retirementNews OS deployment is up in the air after Microsoft's MDT retirement – but the time to take action is now
-
CMA launches Microsoft probe amid software licensing concernsNews The regulator hopes to “ensure a level playing field” when it comes to competition in the business software market
-
Microsoft pledged to simplify Windows 11 updates – it just paused a preview over installation errorsNews Two weeks after pledging to improve Windows 11 updates, a preview suffers installation issues
-
Four things you need to know about GitHub's AI model training policy – including how to opt outNews Users of certain GitHub Copilot plans will have interaction data used to train AI models, but can opt out


