US launches vulnerability information sharing center to address AI-driven surge in vulnerabilities
The Trump administration announced on Tuesday the launch of the Gold Eagle project, aimed at coordinating the use of cutting-edge AI models in vulnerability discovery and remediation to address the surge in vulnerabilities caused by AI. The project will collaborate with Carnegie Mellon University, utilize the VINCE platform, and focus on open-source software, but faces challenges such as coordination with existing industry projects and legal authorization deadlines.

The Trump administration announced on Tuesday the launch of a new program aimed at coordinating secure communities to use cutting-edge AI models to quickly identify and fix software vulnerabilities. The program, named "Gold Eagle," comes against the backdrop of a sharp rise in vulnerabilities discovered by AI models, placing immense pressure on the security community.
As a vulnerability management information-sharing hub, Gold Eagle will have the government coordinate the efforts of private companies and independent researchers to scan, fix, and deploy patches for vulnerabilities in critical software packages to end users. This initiative aims to address the surge in AI-driven vulnerabilities and prevent security experts from duplicating efforts, wasting time and resources.
The White House stated in a release that Gold Eagle "has already begun receiving and prioritizing identified cybersecurity vulnerabilities from various industries and sectors, coordinating scanning and validation, and ultimately ensuring the security of our nation's software and networks."
At the core of Gold Eagle is the "Vulnerability Information and Coordination Environment" (VINCE), a platform operated by the government in partnership with Carnegie Mellon University's Software Engineering Institute. VINCE allows anyone to report vulnerabilities to Gold Eagle for triage and mitigation.
National Cyber Director Sean Cairncross told reporters at a briefing on Tuesday that VINCE will enable "vulnerability and patch coordination at unprecedented speed and scale."
Gold Eagle will focus on open-source software, whose code underpins a wide range of critical infrastructure but often lacks review. Open-source developers, many of whom are volunteers, say they have been overwhelmed by a wave of AI-generated vulnerability reports, some of which are exceptionally accurate. Cairncross called open-source developers "important partners" of Gold Eagle and said their code is vital to American life.
Redundancy and Liability Concerns
The White House describes Gold Eagle as "a coordination system that receives and patches cyber vulnerabilities at unprecedented speed and scale," representing "a new operational model for cyber defense." The program was authorized by President Donald Trump in an executive order on AI safety in June.
However, Gold Eagle launches at a time when the private sector has already established several similar programs. The Linux Foundation, with support from leading tech companies such as Anthropic and Microsoft, created the Akrites project to enhance the open-source community's ability to identify and handle vulnerabilities. Open-source security vendor Chainguard, in collaboration with major enterprises like Cisco, Cloudflare, and JPMorgan Chase, launched Athena, another vulnerability coordination system focused on open-source software.
These two industry-led programs involve frontier AI companies, as well as participants in Anthropic's Project Glasswing and OpenAI's Daybreak consortium. The Trump administration has not specified which companies, including which AI firms, are contributing resources to Gold Eagle. (Anthropic has indicated it will participate in the government-led information-sharing hub.)
One potential obstacle facing Gold Eagle is that its vulnerability information exchange system relies on liability protections under the Cybersecurity Information Sharing Act, which was temporarily reauthorized by Congress in February through the end of September. The Trump administration has called on lawmakers to reauthorize the act for 10 years, saying its protections are essential to a robust cybersecurity collaboration ecosystem.