{"slug": "ostif-ai-use-in-security-research-policy", "title": "OSTIF AI Use in Security Research Policy", "summary": "The Open Source Technology Improvement Fund (OSTIF) has published an Artificial Intelligence (AI) Use in Security Research Policy, effective April 2026 and last updated July 2026, establishing guidelines for responsible AI usage in its security engagements. The policy mandates human oversight of all AI tools, requiring that all AI-generated output be reviewed and approved by a human before publication, and outlines best practices and precautions for secure and private AI implementation, including compliance with intellectual property laws.", "body_md": "# Artificial Intelligence (AI) Use in Security Research Policy\n\n**First version:** April 2026 | **Second version:** May 2026 | **Last updated:** July 2026\n\nRefer to the [OSTIF Open Source Security Audit Minimum Standards & Expectations](https://docs.google.com/document/d/19ug1JSEFs_0-Tj2B4Co7rE7bMkZGDL_45VDKnBD0bNc/) for a quick start guide and security engagement best practices.\n\n*This Policy will be periodically reviewed and updated to address changes in the regulatory landscape and business environment.*\n\n## 1. Purpose\n\nThe Open Source Technology Improvement Fund (OSTIF) Artificial Intelligence (AI) Use in Security Research Policy aims to establish a baseline of responsible usage of AI in security engagements organized by OSTIF. As AI rapidly transforms our sector and reduces time and cost of engagement while increasing the rate of vulnerability identification, it’s important to set expectations around how OSTIF and our contractors will utilize and wield this technology with respect to the open source maintainers, community, and projects we collaborate with.\n\nAs AI rapidly develops and changes, there is hesitancy to set parameters around its implementation. There are valid concerns about the security of data submitted to cloud versus self-hosted models, increased contention around vulnerability ranking and disclosure in open source, and record-breaking amounts of security issues already inundating volunteer maintainers. Clearly defining our relationship with the implementation of AI in OSTIF security engagements is fundamental to our mission as a third-party non-profit organization operating in the cybersecurity space. We’ve always been transparent about the work we’ve done, publishing security work performed on publicly available code used globally by billions. Setting a standard of AI documentation in our reports and disclosures moving forward is a boundary worth setting in this industry as we grapple with the evolving riddle that is security in the AI era.\n\nThis document is meant to be a foundational document, a set of guidelines and expectations around safe, clearly labelled AI usage by employees, representatives, and contractors of OSTIF. It applies to all employees, consultants, representatives, and contractors of OSTIF. The provisions apply globally and all usage of AI must comply with local and global regulations, laws, and corporate guidelines.\n\n## 2. Responsible Use of AI and Legal Compliance\n\nAI tools used or deployed by OSTIF or its representatives must be overseen by a human, and all output generated by an AI must be reviewed and approved by a human before publication or external sharing.\n\nAll usage of AI should follow industry best practices and precautions for secure and private implementation as noted below. Take steps to ensure compliance with intellectual rights regarding generative AI tools with regards to copyright violations and licensing. Reference the list of best practices below or [Linux Foundation’s White Papers](https://lfaidata.foundation/resources/whitepapers/) for more information on industry standards of usage.\n\n## 3. Best Practices for AI Implementation\n\n### Best Practices\n\n- Use AI where it is especially helpful, such as:\n- Automating repetitive tasks;\n- Streamlining and/or centralizing processes and functions;\n- Analysis of large datasets;\n- Trend analysis, recommendation systems, content and response generation and predictions;\n- Informing evidenced based decision-making;\n\n- Use AI programs responsibly and for legitimate business purposes only;\n- Verify that any response from a GenAI tool that you intend to rely on or use is accurate, appropriate, not biased, not a violation of any other individual or entity’s intellectual property or privacy, and consistent with OSTIF Policies and applicable laws.\n\n### Precautions\n\n- Do not use GenAI tools to make or help you make employment decisions about applicants or employees, including recruitment, hiring, retention, promotions, transfers, performance monitoring, discipline, demotion, or terminations;\n- Be cautious when uploading any confidential, proprietary, or sensitive maintainer or project information into any GenAI tool hosted in the cloud (passwords and other credentials, protected health information, personnel material, information from documents marked Confidential, Sensitive, or Proprietary). You must not upload another’s intellectual property to a cloud-based AI tool or system for any reason other than as part of your work, and must take proactive steps to manage any risks before doing so. Such steps should ensure that the cloud-based AI tool or system will not train on sensitive data nor allow others to receive it, including via a contract. Violating this provision may breach your or OSTIF’s obligations to maintain confidentiality and security, risk widespread disclosure, and potentially challenge OSTIF’s rights to that information. If you are unsure, just ask first;\n- Ensure all data is used with respect to the license under which it is released;\n\n- Do not upload or input any personal identifying information (names, addresses, likenesses, etc.) about any other person into any GenAI tool;\n- Use AI programs responsibly and for legitimate business purposes only, and only for the purposes for which they were designed and intended;\n- Be transparent about their use of generative AI for work purposes and acknowledge the generative AI program as the source when used;\n- Verify that any response from a GenAI tool that you intend to rely on or use is accurate, appropriate, not biased, not a violation of any other individual or entity’s intellectual property or privacy, and consistent with OSTIF Policies and applicable laws;\n- When using active AI agent(s), as opposed to simple chat systems, limit the damage they can do. Run the agents within at least one “sandbox” that limits the damage that the AI can do (e.g., virtual machine or container) or on a sacrificial system dedicated to the task. Do not solely depend on an AI to do or not do something because it was instructed through natural language to do so;\n- Enable logging of queries and responses of AI agents. Routinely back those up to a separate system for potential later analysis;\n- Disclose in engagement documentation when and how AI was used in OSTIF funded engagements.\n- This can be general statements like: “Our researchers, assisted by LLM-based tooling with our custom harnesses.”\n- Or specific statements like: “Our researchers used this particular skill on GitHub with Claude Opus.”\n- The importance is transparency about when things are done manually, using (non-AI) tooling, or using LLMs.\n- Unless forbidden, identify the specific AI systems used as part of a report that used them.\n\nAny suspected data leaks or breaches must be escalated immediately to OSTIF Executive Director Derek Zimmer at [[email protected]](/cdn-cgi/l/email-protection#e6828394838da68995928f80c8899481). This notification must be clear, unambiguous, and delivered in language comprehensible to the recipient, specifying whether an AI agent is merely assisting, recording, or actively participating in the exchange.\n\n## 4. Oversight, Accountability, and Governance\n\nOSTIF will oversee the enforcement of this Policy, addressing ethical concerns, legal compliance, and data governance.\n\nWe ask our representatives to cite AI implementation and use in their work with a high-level paragraph in the report, describing how and what work was impacted by AI.\n\nThis Policy will be periodically reviewed and updated to address changes in the regulatory landscape and business environment.", "url": "https://wpnews.pro/news/ostif-ai-use-in-security-research-policy", "canonical_source": "https://ostif.org/ostif-ai-use-in-security-research-policy/", "published_at": "2026-07-31 14:52:49+00:00", "updated_at": "2026-07-31 15:00:41.441380+00:00", "lang": "en", "topics": ["ai-policy", "ai-ethics", "ai-safety"], "entities": ["Open Source Technology Improvement Fund", "Linux Foundation"], "alternates": {"html": "https://wpnews.pro/news/ostif-ai-use-in-security-research-policy", "markdown": "https://wpnews.pro/news/ostif-ai-use-in-security-research-policy.md", "text": "https://wpnews.pro/news/ostif-ai-use-in-security-research-policy.txt", "jsonld": "https://wpnews.pro/news/ostif-ai-use-in-security-research-policy.jsonld"}}