OpenAI's Open-Source Security Scanner Keeps Its Core Locked

OpenAI released Vulnerable Code Detector as open-source while withholding the AI model that performs the vulnerability scanning, making "open-source" functionally meaningless for users who can't run or audit the tool's critical component. This approach reflects a broader industry pattern: companies adopt open-source framing as marketing while keeping proprietary models that deliver value, converting transparency into branding. The gap between the licensed interface and the closed model shows how "open-source" now functions as a positioning claim in AI infrastructure rather than a technical commitment.