ACM Publishes Guide to AI’s New Strain on Open Source

The policy brief sees AI as a tool for finding flaws and writing fixes, but says the people who review, govern and sustain widely used code remain the limiting resource.

By 2 min read
ACM Publishes Guide to AI’s New Strain on Open Source
ACM Publishes Guide to AI’s New Strain on Open Source

Listen to this story

The audio brief

About 1:32
0:001:32
Read transcript
The ACM has published a new policy brief warning that AI could create more work for open-source maintainers, even as it speeds up coding. AI can find vulnerabilities, draft patches and propose contributions. But every proposed change still needs human review before it becomes part of a trusted software release. That makes judgment, not code generation, the immediate bottleneck. The shift cuts both ways. The same tools that help developers discover and fix flaws may also help malicious actors develop attacks against widely used components. A vulnerability in one popular dependency can affect a large number of organizations at once. Yet many organizations do not have a clear picture of which open-source components they use, who maintains them or how secure those components are. The brief recommends software bills of materials to map dependencies, along with active governance of open-source use. It also calls for funding the work AI does not replace: documentation, packaging, usability, fundraising, recruitment and onboarding. That matters because open source already delivers enormous economic value. The brief cites research estimating its value to firms worldwide at 8.8 trillion dollars, and says companies would spend three and a half times more on software without it. Simson Garfinkel of BasisTech chairs the ACM TechBriefs Committee. The unresolved question is whether organizations benefiting from AI-accelerated open source will also invest in the human work that keeps it secure, usable and dependable.

Story brief

3 key points

A new ACM Technology Policy Council TechBrief argues that AI’s biggest near-term effect on open source may be operational: more generated patches and contributions for maintainers to assess, alongside stronger offensive capabilities. The report urges organizations to use software bills of materials, map dependencies, and fund documentation, packaging, security, and community work. The stakes are large: cited...

  1. 01

    AI may improve vulnerability discovery and patching while also helping attackers develop exploits against widely used components.

  2. 02

    Organizations should use software bills of materials to identify dependencies and understand who maintains critical open-source components.

  3. 03

    The brief calls for funding documentation, packaging, usability, fundraising, recruitment, and onboarding—work AI does not replace.

AI can find software flaws, draft patches and speed development. But a new ACM Technology Policy Council brief argues that its fastest-growing effect on open source may be to increase the volume of changes that maintainers must judge before they enter trusted software releases.

The newly published TechBrief, Artificial Intelligence's Effects on Open Source, examines a two-sided shift. AI can help developers identify vulnerabilities, produce patches and accelerate coding. Those same capabilities can also give malicious actors stronger tools to develop attacks against open-source software.

The mechanism is straightforward: coding tools can generate more proposed contributions, but projects still need people to decide which changes belong in a trusted release. The brief identifies that review burden as a maintenance challenge, rather than treating more generated code as an automatic gain in useful software.

AI can dramatically accelerate technical work, but those decisions still require human judgment—at least for now.

Simson Garfinkel, chief scientist at BasisTech and chair of the ACM TechBriefs Committee

Open source’s broad use makes the security tension especially consequential. The TechBrief says AI may improve vulnerability discovery and patching, while also strengthening attackers’ ability to develop attacks. A hidden flaw discovered suddenly can have an outsized effect when the same component is used widely, the brief warns.

That leaves organizations with a practical problem beyond writing code: knowing what open-source components they depend on, who maintains them and how secure they are. The brief says many organizations lack that operational awareness, making it harder to spot critical dependencies before a failure.

What the brief urges organizations to do

  • Use software bills of materials to identify open-source components and dependencies in their software.
  • Map and actively govern their use of open-source software for security and ongoing maintenance.
  • Fund work AI does not replace, including documentation, packaging, usability, fundraising, recruitment and onboarding.

The report places this new workload on top of a longstanding imbalance: projects that create significant value often lack reliable revenue for continued development and support. Its cited research estimates the demand-side value of open-source software to firms worldwide at $8.8 trillion, and estimates firms would spend 3.5 times more on software if open source did not exist.

The brief’s central implication is not that AI makes open source less valuable. It is that technical acceleration does not cover the surrounding work that keeps projects usable and dependable: setting priorities, evaluating contributions, documenting software and building communities. Whether organizations that benefit from open source will devote more resources to that work remains unresolved.

Sources

  1. techxplore.comAI is reshaping open source software and straining the systems that sustain it

Loading discussion...

ACM Publishes Guide to AI’s New Strain on Open Source | Superpower Daily