The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes. It’s the responsibility of the defenders to match that pace. That is why we’ve signed OpenAI’s call for collective action on cyber defense: a call for industry, governments, AI companies, and every organization to strengthen the security of the digital infrastructure we all rely on.
This is not a challenge any one organization can solve alone. It requires shared urgency, practical collaboration, and a commitment to fixing the vulnerabilities that already put critical systems at risk. It also requires a higher standard for the software we build, especially as AI agents transform how that software is created.
The security challenge in the agentic era
Agentic software development is changing the economics and pace of code creation, but it does not change what happens when that code ships unverified. AI coding agents now generate pull requests ten times larger than what developers use to submit, and they do it continuously. The velocity is real. That speed can unlock meaningful productivity, and it can also scale defects, security risks, architectural drift, and technical debt faster than traditional manual review practices were designed to manage.
That speed also creates a verification gap. While code may be functional, it doesn’t mean it’s secure, reliable, maintainable, or compliant. And when code is produced at machine speed, relying on a final manual review or a single check in CI is not enough.
OpenAI’s letter makes this point in cyber-defense terms: longstanding bugs, excess permissions, insecure or unpatched software, weak authentication, and legacy technical debt continue to expose essential services. Its proposed response is direct, saying we must fix the highest-risk weaknesses, verify results, and raise the security bar for what organizations buy, build, and deploy, including AI-generated code. That is the standard Sonar believes agentic development must meet.
That is also why Sonar created the LLM Leaderboard, to give engineering leaders greater transparency into how leading models perform beyond functional correctness. By evaluating AI-generated code for security, reliability, maintainability, and complexity, we are helping organizations make more informed choices about the models they deploy, and reinforcing a core principle of collective cyber defense. No model should be trusted without independent verification.
Collective defense needs zero-trust, multilayered verification
The letter rightly calls for a collective response to broaden access to defensive capability, share practical knowledge and tested playbooks, and measure success by whether fixes work. In software development, that last point is critical. A proposed fix is not a finished fix. It must be independently verified against the security, reliability, maintainability, architecture, and compliance standards that matter.
That is why verification must be zero-trust and multilayered. It shouldn’t depend solely on the same model or agent that generated the code, or on a single method of analysis. Sonar enables intentional, consistent, and transparent verification that combines algorithmic and agentic methods. Algorithmic verification is repeatable and deterministic, built on structural rules and known patterns. Agentic verification applies contextual reasoning to identify logic and behavioral issues. Together, these complementary layers provide stronger assurance than either can deliver alone.
Verification also must happen continuously. It belongs inside the agent’s working loop, at the pull-request and CI gate, and throughout the life of the codebase. We define these as three verification-powered development loops — agentic, CI verification, and code maintenance — through which the Guide, Verify, Solve principles of the Agent Centric Development Cycle (AC/DC) flow. This is how organizations can catch problems near their point of creation, reduce downstream rework, and prevent risk from compounding.
Extending our Collaboration with OpenAI
Sonar is already delivering on the letter's commitments through its collaboration with OpenAI, working together in several ways to help enterprises pair the speed of AI with the safeguards needed to use it responsibly and confidently.
With the SonarQube plugin for Codex and the SonarQube CLI, Codex users can bring Sonar Vortex capabilities into their development workflow, directly in the Codex UX. Sonar Vortex guides agents with the context and constraints they need before they write a single line of code, then verifies agent output in real time, inside the inner loop, correcting security, reliability, and maintainability issues before any PR exists. The result: consistent, explainable verification that leads to healthier code and PRs free of reliability, security, and maintainability issues across teams, tools, and branches.
Additionally, OpenAI’s GPT-5.6 is one of the leading LLMs that powers the SonarQube Remediation Agent, helping it generate proposed fixes for issues in PRs and across the backlog. Sonar then independently re-scans each fix with its analysis engine and raises only verified fixes for developer review. This combines the speed of AI-assisted remediation with the trust that every proposed change meets the organization’s defined standards.
Beyond these integrations, SonarQube Advanced Security secures first-party and AI-generated code, dependencies, and infrastructure; the SonarQube Hunter Agent finds complex flaws like broken access control and business-logic gaps; and Gitar brings contextual AI review to pull requests. Together they give enterprises zero-trust, multilayered verification across the codebase's life.
Trust is the foundation for secure AI adoption
Sonar is the essential trust layer for the AI enterprise software factory. AI can make defenders more capable, but only if it’s deployed with the governance and code verification needed to earn trust. The goal is to make secure, reliable software development possible at the new pace of innovation.
OpenAI’s call is a reminder that the most important cyber-defense work is both urgent and collective. Organizations should make cyber defense a leadership priority, address their highest-risk weaknesses, and hold every change to a standard that is transparent, auditable, and independently verified.
Sonar is proud to support this call. We will continue to help organizations build the code verification and governance foundation required to adopt AI coding tools with confidence, and to turn today’s advances in AI into lasting improvements in security for everyone.

