All posts

IBM, Red Hat launch Lightwell commercial tier for AI code trust

Manaal KhanAugust 11, 2026 at 7:02 PM4 min read
IBM, Red Hat launch Lightwell commercial tier for AI code trust

IBM and Red Hat announced commercial offerings for Lightwell, their open-source platform for software signing, provenance tracking, and policy enforcement. The expansion targets enterprises that need to verify AI-generated code before it reaches production, a problem that grows as more code enters pipelines without human review.

IBM, Red Hat launch Lightwell commercial tier for AI code trust
Source: InfoQ

The new commercial tier bundles artifact signing, provenance generation, policy validation, and lifecycle management into a single supported product. Organizations can now adopt these capabilities without stitching together Sigstore, in-toto, SLSA, and SBOM tooling themselves.

742%
Increase in software supply chain attacks from 2019 to 2022, according to Sonatype's annual reports
Advertisements

Why software trust infrastructure matters now

IBM & Red Hat Lightwell Explained | The Future of Open Source Trust Infrastructure

The timing reflects a shift in how enterprises think about security. Code reviews and vulnerability scans remain important, but they assume a human wrote the code in a known environment. AI agents can now generate code, modify infrastructure, and push changes through delivery pipelines. That breaks the assumption.

Lightwell's answer is cryptographic provenance. Every artifact carries evidence of where it came from, who (or what) built it, whether it was signed with a trusted identity, and whether it has been modified since. Trust becomes an attribute that travels with software from development through deployment, not a checkpoint at the end.

IBM argues this will become foundational. As AI-generated code, open-source components, and automated workflows converge in enterprise pipelines, organizations need a consistent way to verify every stage. The alternative is trusting artifacts that arrived from somewhere, built somehow, by someone or something.

What Lightwell actually includes

The platform builds on standards that emerged over the past several years. Sigstore handles keyless signing and verification. In-toto provides supply chain attestations. SLSA defines levels of assurance for build processes. Software bills of materials (SBOMs) catalog components.

Individually, these projects solve pieces of the problem. Lightwell integrates them into a cohesive workflow. The commercial tier adds enterprise support, lifecycle management, and presumably the operational polish that lets teams adopt it without dedicating engineers to maintenance.

IBM and Red Hat have not disclosed pricing. The open-source Lightwell project remains available for organizations willing to operate it themselves.

Advertisements

The competitive landscape

IBM and Red Hat are not alone. GitHub has expanded provenance capabilities through CodeQL, artifact attestations, and secret scanning. Google drove early adoption of SLSA and Sigstore. Microsoft integrated signing and provenance into Azure DevOps and GitHub Advanced Security.

The Cloud Native Computing Foundation recently partnered with Kusari to strengthen supply chain security across its projects. The Linux Foundation's Akrites project is exploring how cryptographic trust models can protect open-source software more broadly.

This is becoming table stakes for enterprise software delivery. The question for CIOs is not whether to adopt supply chain security tooling, but which platform fits their existing stack and compliance requirements.

ℹ️

Logicity's Take

Lightwell addresses a real gap: AI code generation is outpacing the verification infrastructure. But enterprises evaluating this should also look at GitHub's native attestation features (included in Advanced Security), Chainguard for container signing, and Kusari's open-source tools. The commercial tier's value depends heavily on pricing, which IBM has not revealed. For organizations already deep in Red Hat's ecosystem, Lightwell is the obvious choice. Everyone else should compare before committing.

What this means for AI-assisted development

The deeper implication is that AI agents are becoming participants in software delivery, not just tools. An AI that generates code, modifies infrastructure, or resolves incidents needs an identity, a signature, and an audit trail. Otherwise, you cannot answer basic questions: What made this change? Under what policy? Is it allowed to do that?

Lightwell positions itself as the layer that answers those questions. Whether it becomes the standard depends on adoption across the ecosystem. For now, it is one credible option among several, backed by two companies that control much of enterprise Linux and hybrid cloud infrastructure.

Also Read
Anthropic now watermarks all Claude text globally

Another approach to AI-generated content provenance and verification

ℹ️

Need Help Implementing This?

Evaluating software supply chain security for your organization? Logicity's consulting partners can help you assess Lightwell, GitHub Advanced Security, and alternatives. Contact us for a vendor-neutral review.

Source: InfoQ

M

Manaal Khan

Tech & Innovation Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.