Scaling security with responsible disclosure

TL;DR AI
2 min readKey summary
OpenAI introduced an Outbound Coordinated Disclosure Policy for responsibly reporting vulnerabilities it finds in third-party software.
The policy explains how OpenAI will validate, prioritize, and privately report flaws in both open-source and commercial products.
Timelines are open-ended by default, with public disclosure used only when necessary.
The move is meant to prepare for AI systems that can discover and help fix more security issues across the broader ecosystem.



