Summary
- Prometheus brings together 12 Dutch public, private, and research organisations.
- The initiative aims to develop sovereign, market-neutral AI capabilities for vulnerability discovery and remediation.
- Participants include NCSC, NCTV, TNO, DIVD, VUSec, technology companies, and infrastructure operators.
A Dutch public-private initiative is attempting to build shared defensive capabilities capable of finding and remediating software vulnerabilities at machine speed as autonomous AI changes both offensive and defensive cyber operations.
Prometheus brings together 12 organisations spanning government, research, infrastructure, and the private sector. Participants include the Dutch NCSC, NCTV, TNO, DIVD, VUSec at Vrije Universiteit Amsterdam, NS, ESET, Northwave, Schuberg Philis, and other technology organisations.
The initiative operates under the Digital Holland umbrella and says its objective is to create a market-neutral and sovereign capability that uses artificial intelligence to identify, validate, and remediate weaknesses in widely used software and digital supply chains.
Schuberg Philis, one of the participating organisations, said the founding members will contribute knowledge, infrastructure, technology, data, staff, and practical use cases. The group intends to move successful work beyond research demonstrations into defensive capabilities that can be deployed across sectors.
The project is at an early stage, and its claims about speed and defensive effectiveness remain objectives rather than demonstrated outcomes. The composition of the group is nevertheless notable because it attempts to bridge several parts of vulnerability management that are often handled separately: research, validation, operational deployment, public-sector coordination, and software supply-chain exposure.
AI is already altering the economics of vulnerability research. Models can assist with code review, exploit development, triage, testing, and remediation work, although their output still requires verification and can introduce errors of its own. The same capabilities can reduce the cost of defensive analysis while also increasing the speed at which attackers investigate large software estates.
A collective model could be particularly useful for vulnerabilities in software used across many organisations. Individual users may have little ability to inspect upstream code or influence a supplier’s remediation timetable, even though their exposure depends on the same component. Coordinated research can distribute the cost of identifying and validating weaknesses across a wider ecosystem.
The sovereignty element adds another dimension. European governments increasingly view cyber capability, cloud infrastructure, AI models, and security tooling through the lens of strategic dependency. A domestic or regional capability can reduce reliance on external suppliers in some areas, but sovereignty claims still depend on the underlying technologies, data, compute, and software components used to build the service.
Prometheus will therefore need to demonstrate more than technical performance. Governance will determine who can submit software for analysis, how findings are disclosed, what data can be shared between participants, how high-risk capabilities are controlled, and how remediation decisions are coordinated with vendors.
The initiative’s public-private structure gives it access to expertise across those questions but also creates organisational complexity. Government bodies, commercial security companies, researchers, infrastructure operators, and software specialists do not always share the same incentives or disclosure timelines.
Its early significance lies in the attempt to treat AI-enabled cyber defence as shared infrastructure rather than another standalone security product. Whether that model produces deployable capability will depend on what the founding participants build after the manifesto stage and how transparently its performance can be assessed.





