News

Open-Source AI Security: What a UK Evidence Review Found—and What It Could Not Prove

A UK-commissioned review found major evidence gaps in open-source AI security, warning against treating “open” or “closed” as a complete risk verdict.
AI-generated editorial illustration for “Open-Source AI Security: What a UK Evidence Review Found—and What It Could Not Prove”; conceptual scene, not a real photograph or factual evidence.

A review, not a verdict

A UK government-commissioned study published on 7 September 2026 reviewed cybersecurity literature on open-source software and open-source AI. Led by researchers at the University of Greenwich, it is independent research rather than UK government policy.

What the researchers examined

The publication summary says the team screened 14,561 academic records and included 43 that met its criteria. It reports 172 grey-literature records, supported by analysis of GitHub and Hugging Face. The report’s introduction instead gives 126 grey-literature records, an unresolved internal inconsistency that limits confidence in the reported corpus size.

The central gap

The study found substantial gaps in evidence, particularly around upstream governance of open-source AI. Upstream questions include how models are developed, documented, released and maintained before a deployer adapts them for a specific use.

Why labels are insufficient

“Open source” describes access and licensing choices, not one uniform security condition. Risks can differ between source code, model weights, datasets, interfaces and deployed applications. Closed systems can hide weaknesses; open systems can widen scrutiny but also make powerful components easier to redistribute.

Responsibility across a chain

Security depends on several actors: developers, hosting platforms, distributors, deployers and users. Clear documentation, vulnerability reporting, access controls and update practices can matter more than a single open-or-closed label.

What the evidence cannot prove

A literature review can reveal patterns and blind spots, but it cannot establish that all open models are safer or more dangerous than closed ones. The conclusion depends on the quality and scope of available studies, which the report itself says remain incomplete.

Primary source

Read the official publication page and report. Accessed 12 September 2026.