IBM and Red Hat launch Lightwell to defend open-source code from AI attacks
$5B AI engine and 20,000 engineers protect open-source from AI-discovered exploits.
IBM and Red Hat have transformed their Project Lightwell into two commercial offerings: Lightwell Network and Lightwell Clearinghouse Premier. Backed by a $5 billion AI-powered initiative and 20,000 engineers, the services aim to defend open-source code from the rising tide of AI-driven attacks. Lightwell Network provides immediate access to a growing library of remediated content, including digitally signed binaries, source code, and Software Bills of Materials (SBOMs) delivered directly into existing pipelines without code drift.
Lightwell Clearinghouse Premier acts as a trusted intermediary for advanced industry collaboration, starting with financial services. It allows organizations to submit vulnerabilities and request targeted version remediation under a secured embargo window, with future plans for government, healthcare, and telecom. The core technology is a high-throughput generative AI remediation engine that combines frontier models with human expertise to identify, validate, and backport fixes. Red Hat CEO Matt Hicks called it "a fundamental structural shift in securing enterprise software" against the broken traditional patch model overwhelmed by cheap, AI-generated exploits.
- Lightwell Network is now generally available, offering continuous signed binaries and SBOMs for enterprise open-source stacks.
- Lightwell Clearinghouse Premier is in limited availability for financial services, enabling embargoed vulnerability remediation.
- The $5B initiative uses a gen AI remediation engine with 20,000 engineers to backport fixes and remove dependency on upstream upgrades.
Why It Matters
AI-generated exploits are outpacing traditional patching; Lightwell offers industrial-scale AI defense for critical open-source software.