University of Greenwich Study Maps Evidence Gaps in Open-Source Software and AI Security

Commissioned by DCMS and led by the University of Greenwich, the study reviews academic and grey literature published between 2020 and 2026. It identifies significant evidence gaps, particularly around the upstream governance of open-source AI, and sets out recommendations for addressing them.
New research published by the Department for Digital, Culture, Media and Sport (DCMS) has found significant gaps in the evidence base on the cyber security of open-source software and open-source AI, particularly around the upstream governance of open-source AI.
Commissioned by DCMS and led by the University of Greenwich, the study combines an evidence report with a systematic review of peer-reviewed academic literature and grey literature published between 2020 and 2026. Grey literature covers material published outside traditional academic channels, such as government reports, standards and industry guidance.
The researchers screened 14,561 academic records, of which 43 met the criteria for inclusion, and reviewed 172 grey literature records from national cyber security authorities, standards bodies, international organisations and open-source community organisations. The review was supported by a platform analysis of GitHub and Hugging Face, and the report sets out recommendations for addressing the gaps it identifies.
The research team comprised Dr Srinidhi Vasudevan, Dr Anna Piazza, Guru Krishna Ramakrishnan and Dr Guido Conaldi. The report presents independent findings and does not represent UK government policy, but it supports the government's wider work to understand the cyber security implications of critical and emerging technologies and to strengthen the UK's cyber resilience.
Organisations developing, deploying or relying on open-source software and AI can read the full report on GOV.UK.
Read the report