Eugene Kaspersky offers to testify in the US and provide source code to US authorities amid AG and DNI concerns about potential risks of Kaspersky software
Russian cybersecurity expert Eugene Kaspersky has offered to hand over his global company's code to US authorities as he fights …
Context & Ripple Effects
Two weeks before this offer, the Senate Intelligence Committee sent a secret notice to the Attorney General and Director of National Intelligence warning of potential risks in Kaspersky software, citing the Russian firm's huge US market share. The offer to testify and hand over source code is Eugene Kaspersky's direct response — an escalation of the transparency campaign he has run for years, as a New York Times profile documented, to allay suspicions of Kremlin influence over his company.
The stakes are unusual because antivirus sits deep inside customer systems with privileged access, which is exactly what makes its ownership a national-security question rather than a normal procurement one. Kaspersky's bet is that radical openness — code, testimony, and later independent third-party review of source code and business operations — can outrun the suspicion.
First-order effects
- The AG and DNI now face a concrete decision on whether to accept the testimony and code review or proceed with restrictions despite them, while Kaspersky's large US customer base waits on the outcome.
- Kaspersky concedes a precedent no major vendor has: submitting its core source code to a foreign government's inspection, trading intellectual-property exposure for continued market access.
Second-order effects
- Rival security vendors with state-tied ownership questions get pulled into the same frame — if Kaspersky's code can be demanded, any foreign-owned endpoint vendor's can be.
- US corporate buyers gain a compliance argument for dropping Kaspersky regardless of what the review finds, since the Senate's warning alone shifts liability onto anyone who keeps it deployed.
Third-order effects
- Endpoint security splits along geopolitical lines: trust in a vendor becomes a function of where it is headquartered, not what its detection scores say — a trajectory the corpus bears out in Kaspersky's eventual US exit and the forced migration of American customers to Pango's UltraAV.
- Independent source-code audit becomes the price of admission for security firms operating across rival blocs, institutionalizing a transparency regime that did not previously exist for commercial antivirus.
The trend: Geopolitical distrust is converting antivirus vendors' deep system access into a national-security issue, forcing a choice between radical transparency and market exclusion.