Enterprise Stack

Open Source's Triple Crisis: Funding, Trust, and the AI Contribution Flood

AI Editorial·
open-sourceaimaintainersgithubfundinglicensing
Open Source's Triple Crisis: Funding, Trust, and the AI Contribution Flood

Reading depth

Open source is confronting three interlocking strains: inadequate funding, declining trust and a surge of machine-assisted contributions that is making software cheaper to produce but not necessarily cheaper to maintain. The financial problem predates generative artificial intelligence. Tidelift and The New Stack’s maintainer surveys have repeatedly found that many widely used projects depend on a small number of underpaid or unpaid contributors. GitHub Sponsors and Open Collective data show that donations remain concentrated among visible developers and marquee projects, leaving much of the less glamorous infrastructure beneath corporate software with limited recurring support. GitHub’s August 2026 reduction in public bug-bounty payments, disclosed in its program terms, has added to concern that independent security researchers are being asked to protect a growing software commons for diminishing compensation. The trust problem cuts in both directions. The Register reported that a prominent Haskell contributor was attacked by anti-AI purists after acknowledging the use of AI tools, illustrating how rigid authorship tests can alienate experienced developers. Yet skepticism toward machine-generated code isn’t merely cultural resistance. The Register separately reported that Zig creator Andrew Kelley called Bun’s Claude-assisted rewrite “unreviewed slop that nobody asked for,” while the Zig Software Foundation said reviewability and engineering accountability mattered more than the tool used to produce a patch. Volume magnifies both disputes. GitHub’s Octoverse 2025-2026 report described rapidly expanding use of AI development tools, while estimates synthesized from the Open Source Initiative’s annual survey and maintainer polling by Tidelift and The New Stack put the machine-assisted share of some projects’ incoming contributions at 40% to 60%. Those estimates aren’t a census, but they capture the operational imbalance: generation is nearly instantaneous, while review remains labor-intensive. Companies should regard the result as supply-chain risk rather than internet drama. The OSI survey links maintainer capacity and governance to project resilience, while OpenSSF guidance treats ownership, release practices and security response as measurable risk factors. Enterprises that rely on open source should therefore assess who can merge and publish code, how releases are reviewed, whether maintainers have succession plans and whether the project has durable financing. Without such support, businesses should expect more abandoned packages, contentious relicensing and vulnerabilities that remain unaddressed because nobody is paid to investigate them.