Open by Default After AI: The GDS Guidance and the Enforcement Question
Imported from official source
In early May 2026, NHS England issued a reported internal guidance note, SDLC-8, mandating the removal of public access to several hundred GitHub repositories. The stated reason was AI-accelerated vulnerability discovery. The actual effect was to contradict years of established UK government open source policy with no public consultation, no published threat model, and no evidence the closures removed any meaningful attacker advantage. On 14 May 2026, the Government Digital Service (GDS) and the Department for Science, Innovation and Technology (DSIT) issued guidance titled AI, Open Code and Vulnerability Risk in the Public Sector. It is a direct, technically grounded rebuttal. The guidance reaffirms open by default as the correct posture for publicly-funded code and makes it clear that closing repositories to compensate for poor security hygiene, or a misguided belief in security by obscurity is not an acceptable practice. This brief summarizes what the guidance says, why the NHS England decision was wrong on its own terms, and what both mean for the international open source security community. Background: What NHS England Did and Why It Matters NHS England removed public acce...
This version
- Version
- 2 of 2
- Recorded
- September 24, 2026 17:00
- Change
- Imported change
- Content hash
fd963984f719a29983cf459b25b22d2e- All versions
- Revision history