US launches vulnerability information sharing center to address surge in vulnerabilities caused by AI
The Trump administration announced on Tuesday the launch of the Gold Eagle project, aimed at coordinating the use of cutting-edge AI models in vulnerability discovery and remediation to address the surge in vulnerabilities caused by AI and pressure on the security community. The project, in collaboration with Carnegie Mellon University and based on the VINCE platform, focuses on open-source software but faces challenges such as overlap with existing private sector initiatives and the expiration of CISA's authorization.

The Trump administration announced a new initiative on Tuesday aimed at coordinating secure communities to use cutting-edge AI models to quickly identify and fix vulnerabilities. The program, named "Gold Eagle," comes amid a sharp rise in the number of vulnerabilities discovered by AI models, placing heavy pressure on the security community. Through this vulnerability management information sharing center, the government will coordinate the work of private companies and independent researchers to scan and fix vulnerabilities in critical software packages and deploy the fixes to end users.
As numerous security experts dive into vulnerability hunting, the government seeks to unify their expertise and the cutting-edge AI tools they use in a coordinated manner. The goal is to enable national vulnerability hunters and their AI tools to cover as broad a range of software as possible, avoiding wasted time and resources from repeatedly focusing on the same software, thereby gaining an advantage in the arms race against cybercriminals and state-backed adversaries.
The White House said in a statement that Gold Eagle "has already begun receiving and prioritizing identified cybersecurity vulnerabilities from various industries and sectors, coordinating scanning and validation, and ultimately ensuring the security of national software and networks."
At the core of the Gold Eagle project is the "Vulnerability Information and Coordination Environment" (VINCE), operated by the government in partnership with Carnegie Mellon University's Software Engineering Institute. The VINCE platform allows anyone to report vulnerabilities to the Gold Eagle project for triage and mitigation. National Cyber Director Sean Cairncross told reporters at a briefing on Tuesday that VINCE will enable "vulnerability and patch coordination at unprecedented speed and scale."
Gold Eagle will focus on open-source software, whose code underpins a wide range of critical infrastructure but often lacks thorough review. Open-source developers, many of whom are volunteer maintainers, say they have been overwhelmed by a wave of AI-generated vulnerability reports, some of which are astonishingly accurate. Cairncross called open-source developers "important partners" in the Gold Eagle project and said their code is vital to American life.
Redundancy and Liability Concerns
The White House describes Gold Eagle as "a coordination system that receives and patches cyber vulnerabilities at unprecedented speed and scale," representing "a new operating model for cyber defense." The creation of the project was authorized by President Donald Trump in a June executive order on AI security. However, Gold Eagle launches at a time when the private sector has already established several similar projects. The Linux Foundation, with support from leading tech companies such as Anthropic and Microsoft, created a project called Akrites to enhance the open-source community's ability to identify and handle vulnerabilities. Open-source security vendor Chainguard, in collaboration with major enterprises like Cisco, Cloudflare, and JPMorgan Chase, has also launched Athena—another vulnerability coordination system focused on open-source software.
These two industry-led projects involve frontier AI companies as well as participants from Anthropic's Project Glasswing and OpenAI's Daybreak consortium. The Trump administration has not yet specified which companies are participating in the Gold Eagle project, including which AI companies are contributing resources. (Anthropic has said it will participate in the government-led information sharing center.)
One potential obstacle facing Gold Eagle has already emerged: its vulnerability information exchange system relies on liability protections under the Cybersecurity Information Sharing Act, which was temporarily reauthorized by Congress in February through the end of September. The Trump administration has called on lawmakers to reauthorize the act for 10 years, saying its protections are essential to a robust cybersecurity collaboration ecosystem.