AI Code Tools Strain Open Source Maintenance and Security
Automated contributions flood projects while funding gaps and vulnerability risks widen across critical infrastructure.

Maintainers face mounting review burden
AI coding assistants are accelerating code production faster than open source maintainers can safely review it, according to a new analysis from six authors writing for the Association for Computing Machinery's Technology Policy Council, including Simson Garfinkel and Josiah Dykstra.
The tools excel at writing code and identifying security flaws quickly, but the human maintainers who control what enters official releases must still evaluate every submission themselves. That workload is growing as AI lowers the barrier to contribution, and some of what arrives is poor quality. While model capabilities may improve, the volume of submissions requiring human judgment continues to climb.
Why it matters
Open source code forms the foundation of phones, automobiles, cloud infrastructure, and AI platforms. A Harvard Business School paper cited in the analysis estimates that companies would spend 3.5 times more on software without open source components. When maintenance falls behind on these widely-used projects, security vulnerabilities can propagate across entire technology ecosystems.
Dual-use vulnerability tools accelerate both fixes and exploits
Between April and October 2025, Google's CodeMender agent contributed 72 security fixes to open source projects, some spanning codebases as large as 4.5 million lines, according to Google. But models capable of finding and patching flaws can also be weaponized to construct attacks. The authors doubt that restricting advanced security models to trusted users will provide meaningful protection, since general-purpose models continue gaining strength.
When AI systems discover vulnerabilities in widely-deployed code, organizations face pressure to patch immediately. That creates cascading complexity for applications built from multiple open source components, because each dependency requires its own patch and re-release in sequence.
Funding disparities leave critical projects vulnerable
The Linux Foundation reported revenue of $292 million in 2024. By contrast, the Apache Software Foundation—which the authors highlight as representative of projects running on volunteer labor and sponsorships—brought in $2.4 million, less than 1 percent of that figure. Most open source users never contribute financially, a dynamic known as the free-rider problem. Many projects lack reliable revenue streams, and deferred maintenance on these projects creates security gaps in the software built atop them.
Visibility gaps obscure dependency risks
A software bill of materials (SBOM) provides a machine-readable inventory of components inside an application. Despite mandates from US and EU regulators, the vast majority of open source applications do not generate or distribute one. Even when present, an SBOM reveals only what components exist, not whether each piece is actively maintained, adequately funded, secure, or abandoned.
Because open source operates through project-by-project governance, collecting ecosystem-wide data on AI's effects remains difficult. The authors recommend that projects invest more resources in documentation, packaging, fundraising, and requirements gathering—work that still requires human judgment and community consensus. They identify understanding the governance, maintenance, and security status of software dependencies as perhaps the largest challenge facing most institutions, critical for identifying points of failure before systems break.
These findings were first reported by HelpNetSecurity, drawing on analysis from the ACM Technology Policy Council.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call