OpenAI formalizes bug reporting as AI finds real zero-days
Curated by the Inblix editorial team
OpenAI is publishing a formal Outbound Coordinated Disclosure Policy, a move that sounds bureaucratic but signals something genuinely new: the company’s AI models are already uncovering zero-day vulnerabilities in third-party and open-source software, and the pace is expected to accelerate. This isn’t theoretical. The blog post confirms that systems developed by OpenAI have surfaced real-world security holes, prompting the need for a structured, scalable way to report them responsibly.
The policy covers vulnerabilities found through manual research, internal audits of open-source code the company depends on, and crucially, automated AI analysis. OpenAI is betting that as models get better at reasoning about code, the volume and complexity of discovered bugs will climb. The company describes its principles as impact-oriented, cooperative, and discreet by default, with a strong preference for private disclosure before anything goes public. They’ll validate and prioritize findings, then contact vendors directly.
Interestingly, OpenAI is taking an intentionally developer-friendly stance on disclosure timelines. Instead of imposing a rigid 90-day clock—a common industry practice—the company is leaving timelines open-ended by default. The reasoning is pragmatic: deeper, AI-surfaced bugs may require more time and collaboration to fix sustainably. OpenAI still reserves the right to disclose publicly when it determines there is a public interest in doing so, but the default posture is patience.
This is a quiet but significant milestone. We’ve debated for years whether AI would become a net positive or negative for security. Watching a major AI lab build infrastructure around real vulnerability discoveries—and choosing to cooperate with maintainers rather than weaponize or hoard flaws—suggests the optimistic scenario is actually being operationalized. The unknown variable is scale. If models start flagging bugs faster than maintainers can patch them, even the most cooperative disclosure policy will strain the ecosystem’s capacity to respond.
💡 Key Takeaways
- OpenAI confirms its AI systems have already discovered zero-day vulnerabilities in third-party and open-source software, moving the capability from theoretical to real.
- The company's new policy intentionally leaves disclosure timelines open-ended to accommodate the deeper collaboration complex AI-found bugs may require.
- Automated AI analysis is listed alongside manual research as a source of vulnerability discovery, signaling a future where bug-finding is increasingly machine-driven.
- OpenAI's default stance is private, cooperative disclosure, but it retains the right to go public when there is a public interest in doing so.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.