
Open source runs on a strange social contract: build in public, and others will build on it, fix it, and give back.
AI may be quietly breaking that deal.
Models trained on open-source code can now analyze enormous amounts of software and find vulnerabilities at a scale no human maintainer could match. And finding a vuln can pay — through bug bounties, security research, commercial security tooling, or sometimes worse incentives. Maintaining the project that made the discovery possible? Not so much.
So we're asking the uncomfortable questions:
🍵 Should AI companies contribute back to the open source they're built on?
🍵 What does “fair use” even mean when a model learns from your code?
🍵 When AI finds bugs faster than maintainers can patch them, who's responsible for disclosure?
…and more.