Overview
- Project Lightwell was announced Thursday, May 28, 2026, and IBM says the initiative will move from pilots to a commercial subscription offering within roughly 30 days.
- IBM and Red Hat pledged $5 billion and plan to deploy more than 20,000 engineers who will use AI to scan code, triage findings, write fixes, and validate patches for customer production environments.
- The clearinghouse will let companies confidentially report flaws, receive tested fixes tailored for their systems, and coordinate upstream disclosure so community projects can adopt long-term patches.
- IBM executives said the decision was driven by rapid, AI-driven vulnerability discovery—Anthropic’s Mythos preview found thousands of high- and critical-severity issues—which raises the risk that flaws could be found and exploited faster than they can be fixed.
- Early pilots with major banks and payments firms have been used to shape the service, and IBM expects subscriptions likely priced by number of packages used to give enterprises a ‘stamp of approval’ that code is safe for production.