The biggest weakness in open-source security is not the code itself, but its governance. It is time to build a global, federated model instead of relying on a single gatekeeper.
A coordinated approach to securing open source is long overdue. But if the world’s most sensitive security data is placed under a single jurisdiction, we risk recreating the very vulnerability that such an approach is meant to eliminate.
About three weeks ago, a US export control directive ordered access to two leading AI models to be suspended. Their critical capability was the ability to identify software vulnerabilities at scale. The order applied to all foreign nationals, regardless of whether they were inside or outside the United States. There was no exemption for allies or partners. NATO members were not excluded either. The company affected had no choice but to comply, shutting down the functionality for everyone within hours.
The immediate response was the announcement of a new initiative designed to coordinate the entire vulnerability remediation lifecycle. This is a decisive response to a genuine emergency. Artificial intelligence has not only driven the cost of writing software close to zero, but also dramatically reduced the cost of finding and exploiting software vulnerabilities. In the past, an expert might have spent weeks identifying a serious flaw in a major project. Today, a machine can do it in minutes.
Finding vulnerabilities is one side of the equation. Managing and coordinating their remediation is the other. Maintainers around the world who look after the open-source software that our banks, hospitals and power grids depend on are reaching their limits. A coordinated approach that consolidates this defensive work, eliminates duplication, prioritizes and fixes vulnerabilities across sectors, and funds the unglamorous maintenance that critical infrastructure relies on behind the scenes is long overdue.
But just as important as creating such a project is determining how it will be governed. The question is not whether coordination is necessary, but how that coordination should be controlled. Under the current model, it could create what may become the world’s most security-sensitive dataset: a single repository of known open-source vulnerabilities, providing member organizations with early and confidential access before security updates are available.
It is easy to imagine such a repository being based in the United States, subject to US jurisdiction and potentially accessible to US national security authorities. We have just been shown, in the most direct way possible, why this should concern every stakeholder and every government outside Washington.
A Real-World Scenario, Not a Hypothetical
The export control suspension was not a thought experiment. It was practical proof that a single access point cannot govern a distributed commons. Open source is not a product delivered from a single location. It is a global, federated model of software development involving millions of contributors, thousands of independent projects, maintainers on every continent and dependencies that cross every border.
That distribution is precisely what makes it resilient. Much like the distributed network underlying today’s internet infrastructure, there is no single point of failure, no single owner and no single switch. Directing vulnerability remediation through one centralized repository operating under a single jurisdiction therefore contradicts the very architecture that makes open source trustworthy in the first place. At the same time, it creates exactly the single point of failure that the distributed structure is designed to avoid.
Coordination is necessary. Centralization is the mistake.
Its governance should reflect the underlying architecture of open source and global commons. A distributed commons requires federated oversight, with interoperable nodes following shared best practices, rather than a single gatekeeper. Only a federated governance model can ensure that vulnerability disclosure and remediation move at the same speed as the threat itself, without giving any single jurisdiction, company or server the power to determine who is allowed to defend themselves and when.
The export control suspension was not the first warning. The Common Vulnerabilities and Exposures (CVE) Program, the naming system on which virtually the entire vulnerability remediation ecosystem depends, is operated by a single US nonprofit organization and funded exclusively by the US government.
Last year, it came within days of a potential shutdown when that funding was nearly interrupted. The problem was not an attack, but an ordinary budget cut: a decision made by a single government. The consequences would have been global. Two examples, two different mechanisms, export controls in one case and budget adjustments in the other, point to the same structural reality: no single organization or government should hold the keys to our shared global infrastructure.
Three Precedents, One Lesson for Europe
Europe’s immediate response could be to build a countermodel: a regional repository, a European access point, a sovereign alternative. Similar to the months following the funding crisis, when both the EU and a separate international coalition developed their own systems for identifying vulnerabilities, the EU could establish a European initiative of its own.
The impulse is understandable, but it does not solve the underlying problem of missing distributed governance. A fragmented commons is a weaker commons, and a defensive landscape divided along jurisdictional lines ultimately benefits attackers. The lesson is not that regional systems and initiatives should not exist. The lesson is that regional initiatives must federate rather than consolidate their efforts into a single initiative.
What is needed is a shared, neutrally governed layer beneath these initiatives, not a gatekeeper in every capital.
The world has dealt with shared, cross-border resources that can become dangerous when misused before. The sustainable answer has never been fragmentation. It has been public-private partnership on neutral ground. There are useful examples to learn from: radio spectrum, nuclear technology and life-saving medicines. None of these resources is governed or managed perfectly, and there are particularly strong reasons to consider the nuclear model a failure. Nevertheless, all three examples are worth revisiting.
Radio spectrum is finite, invisible and unusable if everyone transmits at the same time. Since 1906, it has not been governed by a world government, but through a common treaty framework under the International Telecommunication Union. The goal was not to create a world government for radio waves. Sovereign states retained the right to license their own users. What they gave up was the right to cause harmful interference across borders.
Instead, they accepted a common treaty, a shared registry of frequency allocations and a permanent process for reconciling competing claims.
Nuclear technology is the most difficult case because the same capability that can power a city can also destroy an entire nation. It was embedded in the “Atoms for Peace” framework and the International Atomic Energy Agency. States were guaranteed access to peaceful applications in exchange for accepting safeguards and inspections. A neutral organization held both sides of the arrangement together. Notably, the United States initiated and convened the system, but the institution itself was established as a neutral body headquartered in Vienna and governed multilaterally. The initiator was not the owner.
Life-saving medicines protected by patents were not made accessible through expropriation. Instead, access was expanded through the public health flexibilities of the TRIPS Agreement and through pooled, tiered access mechanisms managed neutrally. This allowed private innovators to retain their rights while public authorities ensured access on non-discriminatory terms.
Three different technologies, three different crises, one recurring structure.
The model is one of public-private partnership: the public side provides the rules and guarantees access, the private sector contributes the technical substance while retaining control over it, and a trusted intermediary on neutral ground provides stability. None of these models required the creation of a new sovereign authority. And none allowed the most powerful participant to serve as both gatekeeper and stakeholder.
None was perfect. But all can serve as case studies for developing a solution to today’s software security crisis.
A Constructive Way Forward
This is not a call to abandon the work that has already begun. It is a call to think the concept through to its logical conclusion. The structural observation and the historical perspective point in the same direction. The initiative needs a governance framework. What is required is a durable, resilient and sustainable model built on institutions that already exist. Public authorities can provide legitimacy and guarantees of access. Private providers can contribute technical implementation. And a distributed network of open-source stewards can coordinate efforts and share best practices.
Three commitments could turn a promising announcement into a sustainable initiative.
- First, it should be structured as a multi-stakeholder partnership rather than a repository controlled by a single entity. Federated nodes should work together through shared disclosure practices and interoperability.
- Second, access to AI-powered security capabilities should be subject to a binding non-discrimination commitment. No export order or other national instrument should be able to shut down mutual review and defense of the code on which the entire world depends.
- Third, maintainer support and vulnerability disclosure coordination should be based within a neutral institutional framework. The stewardship of embargoed vulnerabilities should therefore be governed multilaterally rather than left to the discretion of a single state or company.
Against this backdrop, the structural observation and historical context outlined above are intended to encourage thinking beyond the newly announced initiative and toward building a governance framework around it.
The window to establish the right foundations is open today, but it will not remain open forever.
We can secure the global commons together, provided we do not allow a single jurisdiction to decide, in the name of defending it, who gets protected and who does not.