The Trump administration says a new AI-enhanced clearinghouse will dramatically speed up the process of analyzing and fixing software vulnerabilities before hackers can exploit them. But one month after its launch, it’s still unclear how much value the program will create.
The U.S. government’s Gold Eagle clearinghouse, which launched in mid-July, is intended to analyze an AI-fueled tidal wave of bug reports, identify and help patch the most dangerous vulnerabilities and raise awareness about those fixes. But Gold Eagle’s limited scale and voluntary nature raise serious doubts about its ability to corral a vast universe of vulnerability analysis, according to cybersecurity experts. These experts also questioned the Treasury Department’s oversight of the clearinghouse, the funding for its central technology system and the way it will integrate with private-sector vulnerability coordination hubs.
“There’s no need for the government to step in here,” said Alex Stamos, the chief security officer at AI coding security firm Corridor. “The private sector is doing a great job here.”
At the same time, given the scope of the software vulnerability crisis, veteran security researchers said Gold Eagle could be moderately helpful if it uses its limited resources wisely.
“A clearinghouse that validates findings before they hit software maintainers, deduplicates them, and routes fixes to everyone affected would convert AI noise into defensive signal,” said Katie Moussouris, the CEO of Luta Security and a longtime vulnerability disclosure expert. “That is real value if it is executed well.”

Patching prioritization
Most of the limited public information about the clearinghouse comes from an executive order that President Donald Trump issued in June, which directed the government to launch “an AI cybersecurity clearinghouse, in voluntary collaboration with the AI industry and operators of critical infrastructure, that coordinates and deconflicts scanning for software vulnerabilities, discovers and validates such vulnerabilities, and coordinates and prioritizes remediation and distribution of vulnerability patches.”
An Aug. 14 Cybersecurity and Infrastructure Security Agency (CISA) fact sheet described Gold Eagle as “a software capability that, at scale, enables ingestion, validation, and deduplication of AI-enabled vulnerability reporting.”
Experts were highly skeptical that the clearinghouse would help much with scanning and validation.
When it comes to scanning, “deconfliction only works on the people inside the tent,” Moussouris said. “Security researchers around the world will keep scanning whatever they want and reporting their findings directly to maintainers regardless of what this clearinghouse does.”
A more “realistic win,” she said, would be deconflicting government agencies’ own scanning.
As for validating vulnerabilities, experts said that since organizations have refined their use of Mythos and similar models, they have become significantly better at sorting real flaws from AI-generated nonsense. “The validation [concern] is probably a bit outdated,” said Dan Lorenc, the CEO of software security firm Chainguard.
The clearinghouse attracted the most support for its potential role in raising awareness of new patches.
Patching is a multipronged problem for the software industry. Some commercial vendors don’t prioritize patches correctly, many open-source volunteer developers struggle to keep up with fixes, supply-chain opacity makes it hard to untangle code dependencies and end users — especially critical infrastructure operators — lack information about how vulnerabilities could affect them.
The clearinghouse could help solve these problems. The government has a unique understanding of the risk landscape, from nation-state hackers’ espionage and sabotage intentions to cybercrime gangs’ latest target industries. The clearinghouse could use those insights to help developers understand which flaws to patch first, and then to help infrastructure operators apply those patches — or, if they can’t patch bespoke industrial systems, mitigate the risks another way.
“Telling people about a vulnerability and then telling them what action they can take,” Lorenc said, “is a really important role for the government.”
The clearinghouse could make a big difference in open-source software remediation. Participating experts could help developers understand and fix flaws in their code, and when users create their own patches for vulnerabilities in unsupported older versions of software packages, the clearinghouse could raise awareness of those patches.
Gold Eagle could also prod the software industry into adopting a much faster patching cadence. Hackers can now use AI to create exploits for newly discovered vulnerabilities within minutes, but developers haven’t kept pace. In March, Mandiant said that patches lagged behind exploits by an average of seven days. “Our patch management has to speed way up,” said Nick Reese, a former director for emerging technology policy at the Department of Homeland Security.
Time-to-exploit has plummeted
Not everyone is eager to see Treasury’s clearinghouse supervise vulnerability awareness efforts. Stamos pointed out that Congress assigned that role to CISA, before Trump hollowed out the agency, terminated an important collaboration mechanism and froze many partnerships with infrastructure operators.
“We should go back to the system that we had set up for this,” Stamos said. “Restaff [CISA], rebuild the relationships. … There's no reason to recreate any of this.”
CISA said in its fact sheet that it was helping to run the clearinghouse, adding that Gold Eagle would drive “progress towards reducing risk to essential software systems, strengthening critical infrastructure, and bolstering national cybersecurity.”
Funding, leadership and coordination
The government has said very little about how the clearinghouse will work, but the scant available information suggests several major challenges.
The White House has said that the clearinghouse’s intake mechanism for vulnerability reports will be the Vulnerability Information and Coordination Environment (VINCE), run by Carnegie Mellon University’s Software Engineering Institute (SEI), a federally funded research organization that operates the CERT Coordination Center (CERT/CC).
Paul Ruggiero, a senior editor and content strategist at SEI, told Cybersecurity Dive that VINCE “will ingest AI-scale vulnerability reporting, then use automation and AI to analyze and prioritize reports for delivery to the CERT/CC for potential coordinated vulnerability disclosure.”
But experts are concerned that CERT/CC may not be up to the job. Moussouris said the group “is not currently funded with enough analysts to handle a program of this size.” Without additional funding, reports submitted through VINCE could languish for weeks or even months before analysts can review them.
Even a well-funded CERT/CC will only receive reports about a small fraction of the vulnerabilities that the clearinghouse aims to analyze. Most people will continue to report first to the vendors and open-source maintainers responsible for the software. “I don’t think anyone will see that as the first place you go when you find a vulnerability,” Lorenc said, “but it’s a place you go when you know something needs national coordination.”
By building up VINCE as the main repository for data about nationally significant software flaws, the Trump administration has also painted a massive target on its back. Hackers working for criminal gangs and adversarial governments will likely do everything they can to break into the VINCE database.
“Increased centralization of unpatched vulnerabilities is a juicy target for adversaries,” Moussouris said. “Why hack [more than a thousand] open-source projects and closed-source software companies if you can hit the bug jackpot all in one place?”
It is also unclear how the government’s program will integrate with the handful of industry-led vulnerability coordination projects that have launched over the past few months. IBM and Red Hat have launched Lightwell, the Linux Foundation has created Akrites and Chainguard has created Athena.
“The need for a separate clearinghouse, rather than leveraging and increasing the resourcing of the existing vulnerability sharing structures, is unclear,” said Noah Ringler, a former AI policy lead at DHS.
Lorenc said he and other coordinators of industry-led efforts hope to work harmoniously with the clearinghouse (and with one another). “For every vulnerability you find, there's going to be some flowchart about who you tell in what order.”
The Treasury Department’s leadership of the clearinghouse is another point of contention. There are reasons for the arrangement — large banks were some of the first companies to use Mythos — but experts panned the setup, saying Treasury lacked the expertise to manage the clearinghouse. “Vulnerability coordination succeeds or fails on trust, and researchers, maintainers, and vendors have decades of trust built with CERT/CC and working relationships with CISA,” Moussouris said. “Treasury has neither the coordination mission nor those relationships.”

“Don’t boil the ocean”
Amid a host of unanswered questions about how the clearinghouse will work, experts said the government had to address several goals.
For one thing, Treasury will need to build trust in its coordination mechanism by publicly sharing information about success stories. “Establish a baseline now to assess outcomes … or nobody will ever know if this helped,” Moussouris said.
The clearinghouse will also need to keep pace with private-sector innovations on information exchange in the AI era to ensure that the data remains high-quality and suitable for automated analysis.
Most importantly, the Trump administration will need to be realistic about the scope of what it can achieve in the face of a massive problem.
“Don’t boil the ocean,” Moussouris said. “Understand that there is a capacity limit that one organization can handle that is far below the list of all critical infrastructure software and key open source packages, so be deliberate about building capacity.”