cd /news/ai-policy/ibm-and-red-hat-expand-lightwell-to-… · home topics ai-policy article
[ARTICLE · art-91915] src=infoq.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

IBM and Red Hat Expand Lightwell to Strengthen Trust and Governance for AI-Era Open Source

IBM and Red Hat announced an expansion of Lightwell with new commercial offerings to help organizations establish trusted, verifiable software supply chains for AI-assisted development. The offerings integrate signing, provenance, and policy enforcement based on standards like Sigstore, in-toto, SLSA, and SBOM, addressing the need to verify both human- and AI-generated code throughout the delivery lifecycle.

read4 min views1 publishedAug 11, 2026
IBM and Red Hat Expand Lightwell to Strengthen Trust and Governance for AI-Era Open Source
Image: source

IBM and Red Hat have announced an expansion of Lightwell, introducing new commercial offerings designed to help organizations establish trusted, verifiable software supply chains for the age of AI-assisted software development. Building on the open-source Lightwell project, the new offerings aim to simplify software signing, provenance, artifact verification, and policy enforcement, enabling enterprises to ensure that both human- and AI-generated software can be trusted throughout the software delivery lifecycle.

The announcement reflects a growing shift in software security. As AI accelerates software creation, the challenge is no longer simply producing code faster, but proving where software originated, how it was built, whether it has been modified, and whether it complies with organizational security policies before reaching production. IBM argues that establishing a verifiable "trust infrastructure" will become a foundational capability as enterprises increasingly rely on AI-generated code, open-source components, and automated software supply chains.

Lightwell builds upon many of the security standards that have emerged over the past several years, including Sigstore, in-toto, SLSA (Supply-chain Levels for Software Artifacts), and software bill of materials (SBOM) initiatives. Rather than treating signing, provenance, and policy enforcement as independent activities, Lightwell aims to integrate them into a cohesive platform that enables organizations to verify every stage of the software delivery process.

The expanded commercial offerings provide capabilities for artifact signing, provenance generation, policy validation, and lifecycle management, helping organizations implement supply chain security without assembling multiple disconnected open-source projects themselves. This is particularly relevant as AI-assisted development increases both the speed and volume of software changes entering enterprise delivery pipelines.

This has shifted attention toward cryptographic provenance and continuous verification. Rather than relying solely on code reviews or vulnerability scanning, organizations are increasingly seeking evidence that software was built in approved environments, signed using trusted identities, generated from verified source code, and has remained unaltered throughout its lifecycle. In this model, trust becomes an attribute that accompanies software from development through deployment rather than a final security check performed immediately before release.

Rather than introducing entirely new security concepts, Lightwell packages many of these emerging standards into a commercially supported platform that organizations can adopt more easily within enterprise software delivery environments. The emphasis is less on replacing existing security controls than on operationalizing them consistently across increasingly complex development ecosystems.

The announcement also reflects an important evolution in software engineering. Traditionally, software supply chain security focused on preventing malicious code from entering build pipelines. Increasingly, however, organizations need to establish trust not only in source code but also in AI-generated artifacts, automated workflows, infrastructure changes, and autonomous software delivery processes.

As AI agents become capable of generating code, modifying infrastructure, resolving incidents, and contributing directly to software delivery, organizations need mechanisms to verify who, or what, performed each action, under which identity, and according to which policies. This aligns with broader industry efforts around verifiable execution, cryptographic attestations, workload identity, and policy-as-code, all of which seek to make increasingly autonomous software systems transparent and accountable.

IBM and Red Hat are part of a much broader movement toward trusted software supply chains. GitHub has continued expanding provenance capabilities through CodeQL, artifact attestations, and secret scanning, while Google has driven adoption of SLSA and Sigstore across its software ecosystem. Microsoft has integrated software signing and provenance into Azure DevOps and GitHub Advanced Security, and the Cloud Native Computing Foundation (CNCF) recently partnered with Kusari to strengthen supply chain security across cloud-native projects. Meanwhile, initiatives such as the Linux Foundation's Akrites project are exploring how similar cryptographic trust models can protect open-source software from emerging AI-enabled threats.

Although these initiatives differ in implementation, they share a common objective: ensuring that software can be trusted not simply because it functions correctly, but because its entire lifecycle, from source code to deployment, is verifiable, transparent, and resistant to tampering. Lightwell extends this philosophy into the AI era by recognising that trust must increasingly encompass not only human developers but also AI systems participating in software creation.

IBM's expansion of Lightwell suggests that the future of software security will depend less on individual security tools and more on comprehensive trust architectures that span the entire software lifecycle. As AI accelerates development and automation becomes increasingly autonomous, organizations will need stronger guarantees that every artifact, dependency, and deployment can be traced back to a verified source and validated against organizational policy.

── more in #ai-policy 4 stories · sorted by recency
── more on @ibm 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/ibm-and-red-hat-expa…] indexed:0 read:4min 2026-08-11 ·