AI写代码成常态,但开源治理跟不上,这篇论文找出了六种关键差距。
Regulating the Machine Contributor: Governance and Policy Alignment in Open Source
- 通过对比六大组织政策,提炼出治理AI贡献的六个核心维度。
- 发现现有政策在责任、披露、人工监督等方面存在明显缺失。
- 提出可落地的分级治理框架,适配欧盟、美国等主流AI监管体系。
AI辅助软件开发已从行级补全发展到能自主规划修改、编辑文件并提交拉取请求的智能体。然而,开源项目仍基于人类参与设计:贡献协议、行为准则和评审规范均假设存在可追责的自然人。自主或半自主的AI贡献者挑战了这一前提,2025-2026年期间代理驱动事件、生成式垃圾流量激增及平台停摆的记录表明该差距具有实际操作影响。尽管多个开源组织已制定贡献政策,但体系分散,且未与新兴的AI治理框架(欧盟《人工智能法案》、NIST AI RMF结合加州伯克利智性AI轮廓、ISO/IEC 42001与23894)在贡献层面实现对齐。本文采用最相似系统设计,结合指标编码与对SymPy和LLVM的过程追踪,分析六家组织(SymPy、LLVM、matplotlib、OpenInfra、Apache软件基金会、Linux基金会)的政策,构建六维分类体系(披露、责任、人工监督、许可、执行、维护者负担)、有序政策成熟度评分,并将已记录的代理事件映射至各政策失效维度。将这些维度与监管框架比对后识别出双方共同忽视的重叠缺口,最后勾勒出统一的分层治理框架雏形及校准所需实证评估路径。
原文摘要 · Abstract (English)
AI-assisted software development has moved from line-level autocomplete to agents that can plan changes, edit files, and submit pull requests with limited human supervision. Open-source software, however, evolves through a process designed for humans: contributor agreements, codes of conduct, and review norms all assume a legally accountable person who can attest to provenance and answer reviewer questions. Autonomous and semi-autonomous AI contributors strain those assumptions, and the 2025-2026 record of agent-driven incidents, AI-generated nuisance volume, and platform-level shutdowns shows that the gap is operationally consequential. Several open-source organisations have responded with contribution policies, but the result is fragmented, and its alignment with emerging AI governance frameworks (EU AI Act, NIST AI RMF with the UC Berkeley Agentic AI Profile, ISO/IEC 42001 and 23894) is unmapped at the contribution level. We compare policies across six organisations (SymPy, LLVM, matplotlib, OpenInfra, the Apache Software Foundation, and the Linux Foundation) using Most-Similar Systems Design with indicator-based coding and process tracing for SymPy and LLVM. From this we derive a six-dimensional taxonomy (disclosure, responsibility, human oversight, licensing, enforcement, maintainer workload), an ordinal Policy Maturity Score, and a mapping of documented agent incidents onto the dimensions each policy fails to govern. Aligning the dimensions with the regulatory frameworks above identifies overlapping gaps neither side currently closes, and we close by sketching the shape of a harmonised tiered framework and the empirical evaluation needed to calibrate it.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。