IBM and Red Hat have introduced a major programme intended to strengthen the security of open-source software used by research institutions and public-interest organisations.

The two technology companies announced on 4 August 2026 that eligible universities, NGOs and think tanks will receive free access to Lightwell, an AI-powered platform that finds, validates and repairs vulnerabilities in open-source software packages.

IBM and Red Hat said participating institutions would retain control of their confidential information because Lightwell operates within an organisation’s existing environment. The service does not require the companies to access an institution’s proprietary source code, research or private data.

Why the programme is important

Open-source software supports university research systems, educational platforms, humanitarian programmes, policy research and numerous digital services. However, maintaining this software can be difficult for institutions with limited cybersecurity personnel and financial resources.

The rapid growth of AI is also changing the cybersecurity landscape. Artificial intelligence can help defenders identify weaknesses more quickly, but attackers may use similar capabilities to discover and exploit vulnerable systems.

Lightwell is designed to reduce the engineering time required to locate and correct these weaknesses.

Combining artificial intelligence with human expertise

Lightwell uses a generative AI-powered remediation engine alongside IBM and Red Hat engineers. The system identifies vulnerable software dependencies, develops possible corrections and subjects the proposed fixes to technical validation.

Participating organisations will receive:

  • Validated fixes for vulnerable open-source software
  • Digitally signed source code and software binaries
  • Software Bills of Materials, commonly called SBOMs
  • Compliance documentation
  • Fixes designed for software versions already operating in production

Providing corrections for existing software versions is particularly important because organisations may not always be able to perform major upgrades immediately. An upgrade could introduce compatibility problems or interrupt essential research and humanitarian services.

Thousands of packages already repaired

IBM and Red Hat initially launched Lightwell in May 2026 with a reported commitment of $5 billion and the involvement of more than 20,000 engineers worldwide.

According to their latest announcement, the number of validated and remediated package versions available through the programme has increased from approximately 6,500 to more than 8,000. The work reportedly included corrections for 64 previously undisclosed vulnerabilities.

The companies also follow an “upstream-always” approach, under which corrections are submitted to the original open-source communities for review. This means that improvements developed through the programme could eventually benefit users beyond the participating institutions.

Support from the technology industry

Several major technology companies are collaborating with IBM and Red Hat on the broader Lightwell ecosystem. They include Amazon Web Services, AMD, Microsoft, NVIDIA, Intel, GitLab, F5, JFrog, Palo Alto Networks and ServiceNow.

Financial institutions such as Bank of America, Citi, Goldman Sachs, JPMorganChase, Mastercard, Visa and Wells Fargo are also connected to the growing initiative.

Onboarding begins in August

IBM and Red Hat said onboarding for eligible institutions would begin during August 2026. The free-access programme currently covers more than 185 research universities and 100 NGOs and think tanks in the United States.

Although the initial offer is geographically limited, the programme could have wider international benefits if security fixes are accepted and distributed by the open-source communities responsible for the affected projects.