ACM Publishes Guide to AI’s New Strain on Open Source
The policy brief sees AI as a tool for finding flaws and writing fixes, but says the people who review, govern and sustain widely used code remain the limiting resource.
Listen to this story
The audio brief
Story brief
3 key pointsA new ACM Technology Policy Council TechBrief argues that AI’s biggest near-term effect on open source may be operational: more generated patches and contributions for maintainers to assess, alongside stronger offensive capabilities. The report urges organizations to use software bills of materials, map dependencies, and fund documentation, packaging, security, and community work. The stakes are large: cited...
- 01
AI may improve vulnerability discovery and patching while also helping attackers develop exploits against widely used components.
- 02
Organizations should use software bills of materials to identify dependencies and understand who maintains critical open-source components.
- 03
The brief calls for funding documentation, packaging, usability, fundraising, recruitment, and onboarding—work AI does not replace.
AI can find software flaws, draft patches and speed development. But a new ACM Technology Policy Council brief argues that its fastest-growing effect on open source may be to increase the volume of changes that maintainers must judge before they enter trusted software releases.
The newly published TechBrief, Artificial Intelligence's Effects on Open Source, examines a two-sided shift. AI can help developers identify vulnerabilities, produce patches and accelerate coding. Those same capabilities can also give malicious actors stronger tools to develop attacks against open-source software.
The mechanism is straightforward: coding tools can generate more proposed contributions, but projects still need people to decide which changes belong in a trusted release. The brief identifies that review burden as a maintenance challenge, rather than treating more generated code as an automatic gain in useful software.
AI can dramatically accelerate technical work, but those decisions still require human judgment—at least for now.
Simson Garfinkel, chief scientist at BasisTech and chair of the ACM TechBriefs Committee
Open source’s broad use makes the security tension especially consequential. The TechBrief says AI may improve vulnerability discovery and patching, while also strengthening attackers’ ability to develop attacks. A hidden flaw discovered suddenly can have an outsized effect when the same component is used widely, the brief warns.
That leaves organizations with a practical problem beyond writing code: knowing what open-source components they depend on, who maintains them and how secure they are. The brief says many organizations lack that operational awareness, making it harder to spot critical dependencies before a failure.
What the brief urges organizations to do
- Use software bills of materials to identify open-source components and dependencies in their software.
- Map and actively govern their use of open-source software for security and ongoing maintenance.
- Fund work AI does not replace, including documentation, packaging, usability, fundraising, recruitment and onboarding.
The report places this new workload on top of a longstanding imbalance: projects that create significant value often lack reliable revenue for continued development and support. Its cited research estimates the demand-side value of open-source software to firms worldwide at $8.8 trillion, and estimates firms would spend 3.5 times more on software if open source did not exist.
The brief’s central implication is not that AI makes open source less valuable. It is that technical acceleration does not cover the surrounding work that keeps projects usable and dependable: setting priorities, evaluating contributions, documenting software and building communities. Whether organizations that benefit from open source will devote more resources to that work remains unresolved.
Sources
- techxplore.comAI is reshaping open source software and straining the systems that sustain it
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.