Open source software is the invisible infrastructure of modern life. It runs inside mobile phones, automobiles, cloud platforms, and the very artificial intelligence systems now reshaping the global economy. Yet the volunteer-driven and underfunded ecosystem that produces this software is being shaken by a force it helped create: artificial intelligence. A new TechBrief from the Association for Computing Machinery’s Technology Policy Council, titled “TechBrief: Artificial Intelligence’s Effects on Open Source,” examines how increasingly capable AI systems are simultaneously accelerating open source development and straining the security, maintenance, and long-term sustainability of the projects the digital world depends on.
The economic stakes described in the report are staggering. Research cited by the TechBrief estimates that firms would spend 3.5 times more on software if open source software did not exist, and places the demand-side value of open source software to firms worldwide at 8.8 trillion dollars. That figure captures only what companies would otherwise pay, not the enormous downstream value created by products and services built on top of freely available code. In other words, a relatively small community of maintainers, many of them unpaid or lightly funded, effectively underwrites trillions of dollars in global economic activity. When AI changes how that community works, the consequences ripple far beyond the software industry.
The TechBrief’s central finding is a paradox. AI can help open source projects identify vulnerabilities, develop patches, and accelerate development cycles in ways that were unimaginable a few years ago. Machine learning tools can scan vast codebases for suspicious patterns, suggest fixes, and automate repetitive engineering tasks, freeing human developers for more creative work. But the very same capabilities are available to attackers, who can use AI to discover exploitable flaws faster and to craft more sophisticated attacks. Because open source components are so widely reused, a hidden vulnerability that is suddenly discovered can have a disproportionate impact, propagating through supply chains into countless products and services before defenders even know it exists.
This dual-use dynamic is compounded by a flood of AI-generated code. AI coding assistants are rapidly increasing the volume of contributions submitted to open source projects, and maintainers now face the burden of determining which proposed changes should become part of trusted releases. What was once a manageable review process for popular repositories can become an overwhelming torrent of machine-assisted pull requests, some genuinely useful, some subtly flawed, and some potentially malicious. Reviewing code is not simply a matter of checking syntax; it requires understanding intent, context, and long-term architectural consequences. The report warns that the people performing this gatekeeping function, often volunteers with limited time, are being asked to absorb an ever-growing workload without commensurate resources.
Simson Garfinkel, Chief Scientist at BasisTech and Chair of the ACM TechBriefs Committee, emphasized that open source has always depended on more than the ability to write code. Successful projects, he noted, require people to set priorities, evaluate contributions, make governance decisions, and build consensus around the needs of their communities. AI can dramatically accelerate technical work, but those decisions still require human judgment, at least for now. His observation cuts to the heart of the sustainability problem: the scarce resource in open source is not raw coding output but the human attention, trust, and institutional knowledge that hold projects together. Automating code production without strengthening these social structures may simply shift the bottleneck rather than remove it.
Long-term sustainability is perhaps the most persistent vulnerability the TechBrief identifies. Many open source projects that generate enormous value lack reliable revenue streams for continued development and support. The famous disconnect between widespread use and minimal funding has produced high-profile failures in critical infrastructure, and AI threatens to widen the gap. Sustaining production-ready software requires resources for work well beyond coding, including project management, documentation, usability testing, recruitment, and community building. These activities are precisely the ones that AI cannot replace, yet they are chronically underfunded. If organizations and governments continue to extract value from open source without investing in its human foundations, the ecosystem’s resilience will erode even as its output grows.
The report also highlights what it calls the open source knowledge gap. Organizations frequently lack operational awareness of the governance, maintenance, and cybersecurity properties of the open source components they embed in their products. A typical commercial application may incorporate hundreds of third-party libraries, each with its own maintainers, licensing terms, and security posture. When no one inside an organization understands these dependencies, it becomes difficult to identify critical ones before failures occur, whether those failures stem from an abandoned project, an unpatched vulnerability, or a licensing dispute. AI-generated code can deepen this opacity, because developers may incorporate machine-suggested snippets whose provenance and dependencies are not fully understood.
To respond to these challenges, the TechBrief identifies several areas that warrant greater attention from organizations and policymakers. Expanding the use of software bills of materials, known as SBOMs, would help organizations identify the open source components and dependencies within their software, creating the visibility needed for rapid response when vulnerabilities emerge. Mapping and actively governing organizational use of open source would improve both cybersecurity and ongoing maintenance, replacing ad hoc adoption with deliberate oversight. The report also calls for devoting greater resources to project management activities that AI cannot replace, including documentation, packaging, usability, fundraising, recruitment, and onboarding. Finally, it urges serious attention to the long-term sustainability and financial support of open source projects that organizations and governments depend on, arguing that dependence without investment is a recipe for systemic risk.
The release of this TechBrief reflects a broader effort by the computing community to inform public debate as AI transforms software production. ACM’s TechBriefs are designed to complement the association’s policy activities and to inform policymakers, the public, and others about the nature and implications of information technologies. Earlier editions have covered topics such as vibe coding, buying versus building large language models, automated speech recognition, governmental digital transformation, accessibility, and generative artificial intelligence. The Technology Policy Council, which sets the agenda for ACM’s global policy initiatives and coordinates regional committees in the United States and Europe, serves as the central convening point for the association’s interactions with governments, the computing community, and the public on computing-related policy matters.
The message for the trillions of dollars of economic activity resting on open source foundations is clear. AI offers genuine tools for strengthening the software supply chain, from automated vulnerability discovery to faster patching, and open source communities are well positioned to benefit. But the same technologies are amplifying threats, inflating workloads, and exposing the fragile funding model beneath the ecosystem. The future of open source in the AI era will depend less on how much code machines can write and more on whether societies are willing to invest in the human judgment, governance, and community infrastructure that turn code into trusted, secure, and sustainable software. The ACM report suggests that this investment cannot wait, because the systems everyone relies on are already being transformed.
Subject of Research: The impact of artificial intelligence on the security, maintenance, and sustainability of open source software
Article Title: AI Is reshaping open source software and straining the systems that sustain it
Article References: AI Is reshaping open source software and straining the systems that sustain it. (n.d.). Original publication
Image Credits: AI Generated
DOI: Not provided
Keywords: artificial intelligence, open source software, ACM TechBrief, cybersecurity, software maintenance, sustainability, software supply chain, SBOM, code review, technology policy, AI-generated code, digital infrastructure
Cite Scienmag News
Courtney Benton. (October 7, 2026). AI Is Transforming Open Source Software and Testing the Humans Who Keep It Alive. Scienmag. https://scienmag.com/ai-is-transforming-open-source-software-and-testing-the-humans-who-keep-it-alive/
Courtney Benton. "AI Is Transforming Open Source Software and Testing the Humans Who Keep It Alive." Scienmag, 7 October 2026, https://scienmag.com/ai-is-transforming-open-source-software-and-testing-the-humans-who-keep-it-alive/. Accessed 7 October 2026.
Courtney Benton. "AI Is Transforming Open Source Software and Testing the Humans Who Keep It Alive." Scienmag. October 7, 2026. https://scienmag.com/ai-is-transforming-open-source-software-and-testing-the-humans-who-keep-it-alive/

