AI Risk Clock
Doomsday Clock0 min to midnight
🌑 Dark edit
Infosecurity Magazine2026-06-16

Chainguard, JPMorgan, BNY Team Up to Secure Open Source from AI Threats

SafetyIndustry

So three of the wealthiest institutions on Earth have finally noticed that open-source software might be under attack from AI, and they've responded by forming a coalition called Athena. Because nothing says 'decisive action' like naming your security initiative after a goddess who sprang fully armed from Zeus's head — a fitting metaphor for a plan that materialised fully formed without any pesky democratic input. Chainguard, JPMorgan, and BNY have launched their vulnerability intelligence sharing platform, presumably after realising that the open-source ecosystem they've been happily exploiting for free might actually need defending.

The coalition's stated goal is to 'protect open-source software from AI-driven attacks,' which is a bit like the fire brigade announcing they've invented a hose after the building has already burned down. Open-source maintainers, who have been screaming about supply-chain security for years, must be feeling a warm glow of validation — or possibly just the warmth of their laptops overheating from all the new vulnerabilities about to be shared. JPMorgan and BNY, no strangers to massive data breaches, have decided that sharing threat intelligence is the way forward, rather than, say, paying open-source developers a living wage.

Let's be honest: this is less a coalition and more a very expensive PR exercise. Athena will probably produce lots of reports and dashboards, but the real AI threats — automated exploits, model-poisoned code, deepfaked maintainers — will continue to evolve faster than any committee can respond. The gallows humour writes itself: the best way to secure open source from AI threats is to have the AI not be a threat in the first place, but that would require the same people funding this coalition to also fund alignment research. Ha. Good one.

Read this story in another voice
● REC · 2026