IBM and Red Hat announce Project Lightwell that combines AI-powered vulnerability management with 20,000 engineers to strengthen enterprise software supply chains
Defining a new industry model
IBM and Red Hat are investing $5 billion in a new initiative designed to help enterprises secure open source software as AI accelerates both software development and cyber risk.
Called Project Lightwell, the program combines AI-driven vulnerability analysis with a global engineering workforce of more than 20,000 people to create what the companies describe as a trusted enterprise clearinghouse for open source software security.
The initiative reflects growing concern across the technology industry about the security of open source software, which underpins much of today’s enterprise infrastructure and AI development. IBM and Red Hat said advances in frontier AI are increasing both the speed and scale of vulnerability discovery and exploitation.

AI and engineering teams target enterprise software vulnerabilities
Project Lightwell is designed to help enterprises identify, validate and remediate vulnerabilities across large volumes of open source code used in production environments.
The platform will offer commercial subscriptions that allow organizations to integrate validated patches directly into their software supply chains, with enterprise-grade lifecycle management and testing capabilities.
“Open source is the backbone of today’s digital economy and the foundation of modern AI, and we are at an inflection point in how it is built, secured, and scaled,” said Arvind Krishna, Chairman and CEO, IBM.
“With Project Lightwell, IBM and Red Hat are helping define a new industry model, one that brings together AI, engineering expertise, and trusted collaboration, to secure open source software at its source and across the entire supply chain. This is about strengthening trust in the systems that power business, government, and society.”
The initiative builds on IBM and Red Hat’s existing open source ecosystem, which already includes support for technologies such as Linux, Kubernetes, Kafka, Ansible, Terraform, Cassandra and Java.

Major financial institutions join early deployments
IBM and Red Hat said a group of early adopters is already collaborating on Project Lightwell, including Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo.
The companies said feedback from these deployments will help shape how vulnerabilities are identified, validated and remediated across enterprise software supply chains.
The clearinghouse model is designed to allow enterprises to report vulnerabilities through a trusted intermediary framework while receiving validated patches optimized for production environments. IBM and Red Hat also plan to coordinate upstream disclosures with open source communities.
Open source security becomes strategic priority for enterprises
Project Lightwell comes as enterprises face increasing pressure to secure software dependencies across increasingly complex technology environments.
IBM and Red Hat said the initiative will focus on upstream maintenance, AI-assisted vulnerability triage, secure patch development, dependency hardening and release engineering.
The companies also positioned the initiative as a different approach to AI adoption in engineering, emphasizing expanded technical capacity rather than workforce reduction.
Project Lightwell incorporates learnings from broader industry efforts focused on AI and cybersecurity, including Anthropic’s Project Glasswing and OpenAI’s Trust Access for Cyber.
This article was produced by the editorial team at North America Outlook and published as part of the Outlook Publishing global network of B2B industry magazines.
Outlook Publishing delivers industry insights, company stories, and sector coverage across manufacturing, mining, construction, healthcare, supply chains, food production, and sustainability.
North America Outlook provides ongoing coverage of organisations and developments shaping industries across North America.


