Open by Default After AI: The GDS Guidance and the Enforcement Question
Imported from official source
September 2026 By Sal Kimmich and Simon John Executive Summary In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated vulnerability discovery. The actual effect was to contradict years of established UK government open source policy with no public consultation, no published threat model, and no evidence the closures removed any meaningful attacker advantage. On 14 May 2026, the Government Digital Service (GDS) and the Department for Science, Innovation and Technology (DSIT) issued guidance titled AI, Open Code and Vulnerability Risk in the Public Sector. It is a direct, technically grounded rebuttal. The guidance reaffirms open by default as the correct posture for publicly-funded code and makes it clear that closing repositories to compensate for poor security hygiene, or a misguided belief in security by obscurity is not an acceptable practice. This brief summarizes what the guidance says, why the NHS England decision was wrong on its own terms, and what both mean for the international open source security community. Background: What NHS...
This version
- Version
- 1 of 2
- Recorded
- September 18, 2026 11:34
- Change
- Initial
- Content hash
e5755eeba7b27513a7754d656f753ca8- All versions
- Revision history