Skip to main content
Research and analysis

A study of cybersecurity literature on open-source software and AI

A combined evidence report and systematic review of peer-reviewed academic literature and grey literature.

Documents

Details

The Department for Digital, Culture, Media & Sport (DCMS) asked the University of Greenwich to review cyber security literature on open-source software and open-source AI. The review covered academic studies and ‘grey’ literature (material published outside traditional academic channels, such as government reports, standards, and industry guidance). This literature was published between 2020 and 2026. The research aims to give a detailed overview of what current evidence in this area.

The study screened 14,561 academic records, and 43 of these met the criteria for inclusion. It also reviewed 172 grey literature records from national cyber security authorities, standards bodies, international organisations and open-source community organisations. This was supported by a platform analysis of GitHub and Hugging Face. The research found significant gaps in the evidence, particularly on the upstream governance of open-source AI. It sets out recommendations for addressing these gaps.

This report presents independent research commissioned by DCMS. It does not represent UK government policy. The research was led by the University of Greenwich: Dr Srinidhi Vasudevan, Dr Anna Piazza, Guru Krishna Ramakrishnan and Dr Guido Conaldi.

This research supports the government’s wider work to understand the cyber security implications of critical and emerging technologies, and to support the improvement of the UK’s cyber resilience.

Updates to this page

Published 7 September 2026

Sign up for emails or print this page