All terms

Enterprise AI

Patch the Planet

Also known as: OpenAI Patch the Planet

Patch the Planet is the name of an OpenAI initiative applying AI security tooling to find and fix vulnerabilities in widely used open source software. The underlying idea is that automated security research agents can review far more code than human maintainers can, and submit candidate fixes back to projects. Confirm scope, eligibility and participation details with OpenAI's own announcements before relying on them.

What it is

The initiative sits in a broader category of AI-for-open-source-security programmes, where a vendor offers agent-based code review to maintainers who would not otherwise have security resourcing. The agent reads repositories, reasons about exploitable paths, and produces reports or draft patches for human review. Maintainers remain the decision makers on whether a fix is accepted.

Why it matters

Open source underpins most commercial software, and a large share of it is maintained by small, unpaid teams, so unreviewed vulnerabilities become everyone's supply chain risk. Programmes of this type matter to business owners because they change the expected baseline of security hygiene in dependencies. They also matter as a signal that agentic AI is being deployed on real, consequential engineering work rather than demos.

How it works

Participating projects are scanned by an automated agent, which produces findings with reasoning and often a proposed patch. Maintainers triage those submissions like any other contribution, accepting, amending or rejecting them. Organisations mirroring the approach internally point similar tooling at their own repositories and set a policy for how AI-submitted pull requests are reviewed, labelled and merged.

When it applies

It applies when you maintain or depend heavily on open source code, or when you are setting internal policy for how AI-generated security findings and patches are handled.

Examples

  • A maintainer of a widely used library receives an AI-generated report with a draft patch and reviews it alongside community pull requests.
  • An engineering manager adds a label for AI-submitted pull requests so reviewers know to apply extra scrutiny.
  • A company audits its dependency tree to see which critical packages are covered by AI-assisted security review and which are not.

How it is measured

  • Number of valid vulnerability reports accepted by maintainers
  • Patch acceptance rate: merged fixes as a share of submitted fixes
  • Median time from report to merged remediation
  • False positive rate, measured as rejected findings per hundred submitted

Related terms in Enterprise AI

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.