Avatar

Today, I’m excited to announce that Cisco is donating Project CodeGuard to the Coalition for Secure AI (CoSAI). We collectively recognize that securing AI-generated code is a challenge that belongs to the entire industry, and that open collaboration is the path forward. 

Our Journey with Project CodeGuard 

When we first opensourced Project CodeGuard in October 2025, our goal was clear: make secure AI coding the default, not an afterthought. AI coding agents had transformed how our teams build software, but we saw firsthand how quickly vulnerabilities could be introduced (e.g. hardcoded secrets, weak cryptography, missing input validation, and more). 

Project CodeGuard was our answer. We built a model-agnostic framework that embeds security rules directly into AI coding workflows. Rather than catching vulnerabilities after code is written, the framework guides AI coding agents to generate secure code from the start. However, Project CodeGuard is also very powerful for code review and remediation. 

The response from the community exceeded our expectations. Organizations across industries recognized the same challenges we faced and saw Project CodeGuard as a practical solution. 

The Next Chapter 

Cisco has been an active contributor to CoSAI since its founding. We believe deeply in CoSAI’s mission to advance AI security through industry collaboration. Donating Project CodeGuard to CoSAI is a natural extension of that commitment. 

What This Means for Adopters 

If you’re already using Project CodeGuard, nothing changes immediately. The framework remains fully available, and existing integrations will continue to work. What changes is the project’s future trajectory. 

Leading AI organizations such as Google, Anthropic, OpenAI, NVIDIA, and Microsoft are active members and leaders in the CoSAI community. They will continue to contribute to the project and help it evolve. We will also collectively help promote the project and raise awareness about the importance of secure AI coding. 

Cisco’s Continued Commitment 

Donating Project CodeGuard doesn’t mean Cisco is stepping away. We remain deeply committed to the project’s success. We have dedicated security and AI engineers that will continue contributing agent skills, rules, translators, and improvements. 

We have been applying Project CodeGuard internally across the Cisco ecosystem with great success. We’ll collaborate with CoSAI members to expand the framework’s capabilities. This donation is an investment in the project’s long-term success. 

The Bigger Picture 

Project CodeGuard is one piece of Cisco’s broader commitment to AI security. We continue to develop and contribute open-source tools like the MCP Scanner, A2A Scanner, and Agent Skills Scanner for securing the AI agent supply chain. 

Learn more about Project CodeGuard at project-codeguard.org. For information about Cisco’s AI security initiatives, visit our AI security blog. To learn more about the Coalition for Secure AI, visit coalitionforsecureai.org. 

Get Involved! Access the framework at CoSAI’s Project CodeGuard GitHub repository and contribute to the project. Together, we can make secure AI generated code the standard, not the exception. 

Authors

Omar Santos

Distinguished Engineer

Cisco Product Security Incident Response Team (PSIRT) Security Research and Operations