# GDS Guidance

Published articles for GDS Guidance.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Open by Default After AI: The GDS Guidance and the Enforcement Question

DevFeed: [Open by Default After AI: The GDS Guidance and the Enforcement Question](<https://devfeed.tech/articles/open-by-default-after-ai-the-gds-guidance-and-the-enforcement-question-42826.md>)

Original publisher: [Read original article](<https://openssf.org/blog/2026/09/10/open-by-default-after-ai-the-gds-guidance-and-the-enforcement-question/>)

Author: OpenSSF

Published: 2026-09-10T08:20:35Z

Content type: article

Language: en

Sources: [Open Source Security Foundation](<https://devfeed.tech/sources/open-source-security-foundation.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-vulnerability-discovery](<https://devfeed.tech/tags/ai-vulnerability-discovery.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu-cyber-resilience-act](<https://devfeed.tech/tags/eu-cyber-resilience-act.md>), [gds-guidance](<https://devfeed.tech/tags/gds-guidance.md>), [github](<https://devfeed.tech/tags/github.md>), [government](<https://devfeed.tech/tags/government.md>), [guest-blog](<https://devfeed.tech/tags/guest-blog.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [public-sector-policy](<https://devfeed.tech/tags/public-sector-policy.md>), [security](<https://devfeed.tech/tags/security.md>), [uk](<https://devfeed.tech/tags/uk.md>)

### AI overview

This article examines NHS England's closure of public GitHub repositories after AI-assisted vulnerability findings and the subsequent GDS and DSIT guidance reaffirming open by default for publicly funded code. It argues that repository closures lacked a credible technical basis and raises broader questions about government-wide security governance and enforcement.

### Source excerpt

Discover how new GDS guidance on AI addresses NHS England's repository closures, reinforcing open-by-default security for public sector code.