Big tech is clamping down on open source ‘AI slop’ reports
Firms including Microsoft, OpenAI, and Google have pledged funding to bolster open source security and cut down on slop reports
A host of big tech firms have handed over $12.5 million in funding to advance open source security and try to eliminate "AI slop" bug reports.
Firms including OpenAI, Anthropic, AWS, Google, Microsoft, and GitHub have pledged funding for Alpha-Omega and the Open Source Security Foundation (OpenSSF), both security initiatives within the Linux Foundation.
The aim is to develop long-term, sustainable security solutions that support open source communities worldwide.
The move comes as open source maintainers contend with an unprecedented number of security reports, many of which are generated by automated systems.
Mark Ryland, director of the Office of the CISO for AWS, said these AI-generated reports are overwhelming their ability to review them.
"Many of the reports are of very low quality — a reality given rise to the new industry term 'AI slop'," he said. "Many projects have already elected to put guidelines in place for AI submissions, while others have shut down upstream contributions entirely to prevent a flood of AI-generated pull requests."
Closer ties with open source maintainers
The new investment will allow Alpha-Omega and OpenSSF to work directly with maintainers and their communities to make emerging security capabilities accessible, practical, and aligned with existing project workflows.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“Grant funding alone is not going to help solve the problem that AI tools are causing today on open source security teams,” said Greg Kroah-Hartman of the Linux kernel project.
“OpenSSF has the active resources needed to support numerous projects that will help these overworked maintainers with the triage and processing of the increased AI-generated security reports they are currently receiving.”
The GitHub Secure Open Source Fund is adding an additional $5.5 million in Azure credits and funding to provide training and expertise.
GitHub Security Lab, meanwhile, is improving the security advisory experience on GitHub and Private Vulnerability Reporting (PVR) features, with an eye on reducing the burden of low-quality reports and helping maintainers manage increased volume.
Google, meanwhile, will provide AI-powered tools like Big Sleep and CodeMender from Google DeepMind – already used to protect the company's own systems. It's also extending research initiatives like Sec-Gemini to open source projects.
“Our commitment remains focused: to sustainably secure the entire lifecycle of open source software,” said Steve Fernandez, general manager of OpenSSF.
“By directly empowering the maintainers, we have an extraordinary opportunity to ensure that those at the front lines of software security have the tools and standards to take preventative measures to stay ahead of issues and build a more resilient ecosystem for everyone.”
AI slop reports are skyrocketing
Concerns about AI slop bug reports have been voiced by a number of organizations, including the Python Software Foundation.
Developers behind cURL, an open source command line interface (CLI) tool which allows developers to transfer data, recently shut down its bug bounty scheme in response to a growing number of slop reports.
As ITPro reported at the time, lead maintainer Daniel Stenberg said the current volume of submissions is placing a “high load” on the security team.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Qnap TS-432XeU reviewReviews Some compromises, but Qnap's little rack NAS is an affordable choice for small businesses with limited budgets and office space
-
Slicing through the static: why data quality is the channel’s ultimate competitive advantageIndustry Insights There's real risk from fragmented telemetry for channel partners...
-
GitHub outage blamed on misconfigured policy as firm pledges resilience improvementsNews “Network saturation” in a key data center hosting location sparked the lengthy GitHub outage earlier this week
-
Vibe coding startup Cursor just launched a GitHub alternative – here's what users can expectNews Cursor could muscle in on GitHub’s dominance, but the startup has its work cut out
-
The GitHub outage explained: What happened, who was affected, and how long did it last?News An eight-hour GitHub outage saw an error rate of 50% for repo downloads and major disruption to Actions, APIs, and Copilot
-
Forward deployed engineers are big tech’s latest gambit to drive AI adoptionNews With Microsoft and AWS placing their faith in forward deployed engineers, enterprises will gain a helping hand with tricky AI adoption projects
-
Why is Windows 11 so disliked by programmers – and can Microsoft do anything to change things?Windows isn't the most useful OS in the eyes of developers, with programmers preferring macOS or Linux. But is its bad reputation uncalled for?
-
Anthropic is increasing Claude Code usage limits — here’s everything you need to knowNews The new deal will help Anthropic increase Claude Code usage limits, and API rate limits for Claude Opus models
-
'We are focused on fundamentals, prioritizing quality, and serving our core users better': Satya Nadella teases big Windows improvements – and changes could come this yearNews Satya Nadella told analysts that Microsoft is doing “foundational work to win back fans” across Windows, Xbox, Bing, and Edge
-
Microsoft pats itself on the back over European commitmentsNews The company says it's been working to boost the bloc's digital sovereignty and resilience