The new managed application security service deploys OpenAI's frontier AI models within IBM's security workflow to automatically surface, prioritize, and validate vulnerabilities . It uses read-only, governed access inside client environments, meaning it can analyze code and configurations without altering them
. The service is designed to handle machine-speed threats by extending beyond simple vulnerability discovery into risk triage and actionable fix recommendations
.
Project Lightwell, announced on May 28, 2026, is a $5 billion commitment by IBM and Red Hat that deploys over 20,000 engineers and uses agentic AI techniques to create a trusted enterprise clearinghouse for open-source software security . The new managed application security service extends Lightwell's AI-driven patching and validation capabilities from the open-source supply chain into enterprise application security workflows
. Together, the two initiatives aim to close the gap between vulnerability discovery and automated, validated patch deployment at machine speed
.
IBM's announcement coincided with OpenAI's broader Daybreak expansion, which included an updated GPT-5.5-Cyber model, a Codex Security plugin update to accelerate vulnerability discovery and patching, and the launch of the Daybreak Cyber Partner Program itself . The program is designed to enable security partners to scale the benefits of OpenAI's most capable models with trusted access in their products and services
.
Major financial institutions including Bank of America, JPMorgan Chase, Visa, Mastercard, Wells Fargo, and Morgan Stanley were among the initial users of Project Lightwell . The new managed application security service, while separate, extends the same AI-driven security approach into enterprise application security, potentially serving the same class of large enterprise customers.
Comments
0 comments