OpenAI Outbound Coordinated Disclosure Policy
OpenAI has published an Outbound Coordinated Disclosure Policy to establish a standardized, responsible framework for reporting security vulnerabilities discovered in third-party and open-source software. This policy is a proactive measure to manage the increasing capability of AI systems to identify and patch security flaws, as OpenAI's systems have already uncovered zero-day vulnerabilities.
Technical Discovery and Scope
The Outbound Coordinated Disclosure Policy covers vulnerabilities identified through several channels, including automated analysis using AI tools, targeted audits of open-source code utilized by OpenAI, and ongoing research. The policy applies to both commercial and open-source software, including discoveries made during internal usage of third-party systems.
Disclosure Mechanics and Principles
OpenAI's disclosure process is designed to be cooperative and low-friction for software maintainers. The policy outlines specific procedures for:
- Validation and Prioritization: Establishing how findings are validated before reporting.
- Vendor Contact: Defining the mechanics of how OpenAI contacts vendors to report issues.
- Publicity: Maintaining a non-public disclosure approach by default, unless specific details necessitate a public announcement.
- Core Principles: Operating under principles of being impact-oriented, cooperative, discreet by default, and providing attribution when relevant.
Developer-Friendly Timelines
OpenAI has adopted an open-ended timeline for disclosure by default. This developer-friendly stance is the reason for why the AI-driven nature of vulnerability discovery is evolving; as AI models become more effective at reasoning about code and generating patches, they may detect a greater number of bugs of increasing complexity. This approach allows for deeper collaboration and more time to resolve vulnerabilities sustainably without imposing rigid deadlines on maintainers.
OpenAI reserves the right to disclose vulnerabilities when it determines there is a significant public interest in doing so.
Communication and Feedback
OpenAI encourages communication with software vendors and the rest of the security community. For questions regarding their disclosure practices, the organization provides a dedicated contact email: outbounddisclosures@openai.com.