Study finds AI contribution policies in open source are largely unenforceable
A developer analyzed 2,204 recently merged AI-generated pull requests across public GitHub repositories to assess how enforceable open-source AI contribution policies actually are. The scan found that none of the PRs declared a machine-checkable scope, meaning policies requiring human reviewers to verify a change matched its intended purpose cannot currently be enforced. Around 3.9% of the AI-authored PRs modified agent control files such as AGENTS.md or CLAUDE.md, which steer future agent behavior and represent a subtle privilege-escalation risk most policies do not address. Roughly 13% of PRs touching CI workflows raised GitHub Actions permissions, and 17% introduced unpinned actions — supply-chain risks invisible to authorship-focused policy language. Smaller repositories with fewer than 10,000 stars showed nearly double the finding rate of larger projects, suggesting the least-resourced maintainers are most exposed despite having recently adopted these prose-based policies.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in