Dive Brief:
- AI generated code is proliferating faster than open source software developers can check the results, according to a brief from the Association for Computing Machinery published last week.
- ACM researchers acknowledged AI’s positive impact on open source development, but cautioned that AI agents give attackers more powerful tools and compound longstanding challenges around project maintenance, governance and funding. They also increase the volume of code maintainers must evaluate.
- For partners, the impact of AI on software services is multifold. “MSPs and IT professionals are not only managing their own software, but also the underlying dependencies that come from using open source models that are maintained outside their organization,” co-author and member of the ACM U.S. Technology Policy Committee Shrinivass A.B. said. “With the help of AI assistance, we can identify vulnerabilities and develop patches faster, but the responsibility to review the software has also increased.”
Dive Insight:
Open source software is practically ubiquitous, supporting cloud computing, system administration and internet applications. ACM researchers estimate that global demand for open source among sits at $8.8 trillion. Without access to open source, software spending would more than triple, per the report.
While AI offers automated security fixes and accelerated code development, it also elevates cybersecurity risks. Threat actors have injected malicious code into popular OSS repositories, according to the brief.
AI is also changing the makeup of widely available code. The researchers said AI agents can easily modify open source software, but it’s difficult for code maintainers to keep up with the changes. Agentic systems generate implementation patches quickly, but they can’t replace humans who determine requirements, priorities and community consensus for open source software.
Partners will have to adapt to AI-driven changes and improve visibility into the open source components their customers use, A.B. said.
“As vulnerabilities and dependencies change over time, partners can assist with continuous dependency analysis and strong review and testing practices,” he said. “AI can assist with most of the process like automating parts of vulnerability discovery, patching and testing, but human accountability remains important in deciding what should ultimately be trusted and deployed in a production environment.”
Understanding the scope of the challenges is difficult. Open source software is largely governed on a project-by-project basis, making it difficult to collect ecosystem-wide statistics, according to the brief.
Despite the current challenges, A.B. expects AI to become deeply integrated with the software development lifecycle: from generating code and identifying vulnerabilities, to testing and proposing patches.
“As generating software becomes easier, developers and maintainers will focus more of their efforts on verification, looking into who and what produced this change, if it can be trusted and who is accountable for maintaining it,” he said. “In the case of MSP and IT partners, this could make software supply chain visibility and continuous monitoring an increasingly important part of the value they provide to their customers.