Autopsy of an Autonomous Incident: When the Agent Made It Worse
-
Navin Pai
StackGen
Director of Engineering
November 25–26, 2026
Bengaluru, India
Joining remotely?
Watch live with ProOpen source has always run on a simple trust model: contributions are scarce, contributors are known, and review keeps quality high. AI broke all three assumptions at once.
Maintainers are already closing the door: some projects now ban drive-by AI PRs outright. But closing the door isn’t the answer. Maintainers need to prepare their repos for AI coding assistants rather than push well-meaning contributors away.
This talk argues the OSS trust model needs five concrete operational changes.
Provenance over identity: Review the path a change took, not just who pushed it. Patterns: signed agent attestations, PR templates that surface generation context, and CI provenance checks.
Agent declaration standards: Require contributors to declare which tool generated a PR, a DCO for the agentic era.
Layered triage: Automated reviewers handle style, security, and test coverage, giving contributors faster feedback and freeing maintainers for higher-order decisions.
Sandboxed execution for untrusted code: Test external contributions in isolated environments so a malicious or broken PR can’t poison the build cache or compromise the code.
Self-healing CI: When the build breaks, an agent opens a fix PR rather than waiting for a human.
Drawing on real-world experience and lessons, this session also addresses what doesn’t change: code of conduct, governance, and community health matter more than ever when contributors are non-human.
Conference India 2026
Navin Pai
StackGen
Director of Engineering
Sajeetharan Sinnathurai
Microsoft
Principal Product Manager
Animesh Dutta
Arm
Senior Software Engineer
Aishwarya Mathuria
Adobe
Computer Scientist
Nishant Thakur
Adobe
Senior Computer Scientist