> Markdown version of [/videos/100031-building-on-open-source-the-new-product-playbook?t=554](https://www.wearedevelopers.com/videos/100031-building-on-open-source-the-new-product-playbook?t=554). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Building on Open Source: The New Product Playbook AI is drowning open-source projects in automated pull requests. Is your engineering team prepared to shift from writing raw syntax to deeply vetting AI-generated code? - **Speakers:** [Cédric Gégout](https://www.wearedevelopers.com/@cedric-gegout), [Dana Lawson](https://www.wearedevelopers.com/@dana-lawson), [Michael "Monty" Widenius](https://www.wearedevelopers.com/@michael-monty-widenius), [Sebastian Kister](https://www.wearedevelopers.com/@sebastian-kister), [Ignacio Riesgo](https://www.wearedevelopers.com/@ignacio-riesgo) - **Event:** World Congress 2026 Europe - **Published:** July 9, 2026 - **Duration:** 32:07 - **URL:** https://www.wearedevelopers.com/videos/100031-building-on-open-source-the-new-product-playbook ## Summary The digital foundation of modern software relies heavily on open source, which currently powers 96% of the global software supply chain. However, maintaining this crucial infrastructure faces unprecedented challenges in the AI era. While AI acts as a powerful onboarding tool that helps new contributors learn large codebases faster, it simultaneously floods projects with massive volumes of automated pull requests. This shift demands a change in the developer's role from writing raw syntax to deeply understanding architectural intent and rigorously vetting AI-generated code before committing. Maintainers are not being replaced by AI; instead, their critical review and quality-control skills are more essential than ever to prevent widespread security vulnerabilities. To sustain this ecosystem, organizations must move beyond treating open source as a passive commodity or a mere legal compliance issue. Establishing a modern Open Source Program Office (OSPO) allows companies to transform risk management into strategic engineering alignment. By contributing directly upstream rather than exclusively purchasing enterprise licenses, organizations gain critical visibility into their software supply chain and can proactively resolve architectural bottlenecks. Relying on government funding is historically unsustainable; true viability requires enterprise consumers to invest ethically and financially back into the core projects upon which they depend. Ultimately, the open-source community thrives on a culture of transparency that strengthens code quality through public scrutiny. Businesses can no longer afford to be just consumers—allocating even a fraction of the budget saved by using open-source tools toward direct project sponsorship ensures long-term stability. Embracing modern DevOps practices and agentic workflows will help manage the growing maintenance burden, solidifying a collaborative development model where humans and artificial intelligence work together to secure the open web. **Keywords:** open source sustainability, software supply chain security, AI code generation challenges, open source program office, OSPO, enterprise open source economics, upstream software contributions, agentic developer workflows, maintainer burden, open source licensing models, automated pull request volume, AI developer onboarding, transparent code quality, open web democracy ## Chapters 1. **Open source dominance in the global software supply chain** (01:01) — The modern software supply chain relies almost entirely on open-source components requiring dedicated enterprise maintenance. 1. **Navigating security risks in AI-assisted open source contributions** (03:58) — Increased use of artificial intelligence introduces unresolved vulnerabilities and demands stricter software security audits. 1. **Managing maintainer workload amidst AI coding agent proliferation** (05:33) — The surge of automated pull requests requires maintainers to scrutinize code quality more rigorously to prevent system-wide failures. 1. **Preserving human oversight in the shared responsibility infrastructure** (07:15) — Automated tools cannot replace the critical reasoning and context mapping provided by human infrastructure maintainers. 1. **Building viable economic models for open source operations** (09:14) — Choosing the right licensing model is essential for generating revenue to pay dedicated software maintainers. 1. **Empowering enterprise engineering through open source program offices** (10:13) — Dedicated program offices guide corporate developers to safely and effectively contribute back to upstream initiatives. 1. **Structuring lasting business cases beyond government funding initiatives** (12:26) — Sustainable open-source maintenance relies on viable economic models and corporate support rather than temporary institutional grants. 1. **Gaining software supply chain visibility through upstream engagement** (14:10) — Participating directly in upstream development eliminates vendor bottlenecks and secures control over essential infrastructure dependencies. 1. **Accelerating contributor onboarding with artificial intelligence learning tools** (17:50) — While artificial intelligence accelerates code generation for newcomers, experienced maintainers must still validate integration quality manually. 1. **Shifting developer paradigms from language syntax to strategic intent** (20:58) — Modern developers must focus on mapping project intent and selecting appropriate computational models rather than memorizing programming syntax. 1. **Sustaining digital open operations through modern devops practices** (22:24) — Comprehensive continuous integration systems form the necessary technical foundation for managing code flows generated by autonomous agents. 1. **Maintaining human accountability for artificial intelligence code generation** (25:18) — Engineers must completely comprehend and take personal responsibility for any automated code suggestions they merge into repositories. 1. **Balancing upstream innovation velocity with enterprise system stability** (27:13) — Collaborative maintenance protocols ensure that corporate platforms receive reliable support despite the rapid pace of open innovation. 1. **Finalizing open source challenges and fostering enterprise contribution** (28:42) — Technology leaders urge corporate executives to allocate software savings directly into funding the essential upstream projects they depend heavily upon. ## Related Moments - [The impact of open source models on industry dynamics](https://www.wearedevelopers.com/videos/1311-graphs-and-rags-everywhere-but-what-are-they-andreas-kollegger-neo4j) (from "Graphs and RAGs Everywhere... But What Are They? - Andreas Kollegger - Neo4j") - [Balancing open source contributions with sustainable careers](https://www.wearedevelopers.com/videos/604-can-you-build-a-career-in-open-source) (from "Can you build a career in open source?") - [The global impact of open source software development](https://www.wearedevelopers.com/videos/604-can-you-build-a-career-in-open-source) (from "Can you build a career in open source?") - [Handling the surge of AI-generated open-source code contributions](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) (from "Fighting the Next Wave of Cybercrime") - [Balancing open source access with enterprise monetization](https://www.wearedevelopers.com/videos/1906-rag-s-not-dead-you-re-just-using-it-wrong-phil-nash) (from "RAG's Not Dead, You're Just Using It Wrong! - Phil Nash") - [Refocusing Hacktoberfest on open source artificial intelligence](https://www.wearedevelopers.com/videos/2137-what-to-do-about-hackathons-in-the-time-of-agents-mike-swift) (from "What to Do About Hackathons in the Time of Agents - Mike Swift") ## Related Articles - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) - [Exploring AI: Opportunities and Risks for Developers](https://www.wearedevelopers.com/magazine/522-exploring-ai-opportunities-and-risks-for-developers) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) ## Related Jobs - [Principal Product Manager, Agent Platform](https://www.wearedevelopers.com/jobs/ext/277541-principal-product-manager-agent-platform) at **GitHub** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Senior Software Engineer, Enterprise Products](https://www.wearedevelopers.com/jobs/ext/1841248-senior-software-engineer-enterprise-products) at **GitHub** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Staff Software Engineer, Copilot Experiences](https://www.wearedevelopers.com/jobs/ext/164361-staff-software-engineer-copilot-experiences) at **GitHub**