GenAI : opportunité ou menace pour l'open source ?

#75 – [AI and Open Source] Generative AI (GenAI), opportunity or threat to Open Source?

Generative AI (GenAI), opportunity or threat for Open Source?

Walid: Hello and welcome to Projets Libres, the LinuxFr.org podcast that talks about free software, digital commons and open data. I’m Walid Nouh and today we’re starting a series on artificial intelligence and free software. A series of dialogues with people who have opinions on the subject, whether positive or negative. We’re going to see the different aspects around these new technologies. And to start today, we have with us Marie-Alice Blete, who is an AI engineer, but I’ll let my colleague Raphaël Semeteys introduce this in more detail since he is the one who is at the origin of the series.

Raphaël: Yes, thank you very much. Hi everyone. Super happy to talk about these two subjects that fascinate me, and how they interfere and how they impact each other. And I did a conference on the subject not too long ago. And now I’m super happy that Marie-Alice, a former colleague of mine, agreed to come and discuss this subject with us. But Marie-Alice, I’ll let you introduce yourself.

Marie-Alice: Thank you Raphaël. I’m really happy to be able to participate. So my name is Marie-Alice Blete. I’m an AI engineer. And my expertise is more in artificial intelligence than open source, but artificial intelligence allowed me to make my first, or maybe one of my first contributions recently. So I’m happy to be able to bring this testimony.

Raphaël: Great. And you’re also an author?

Marie-Alice: Absolutely. I wrote a book in 2023, so at the very beginning of generative AI (GenAI), which is called Developing Apps with ChatGPT and GPT-4, which is published by O’Reilly.

Walid: What profile do you have? What did you do before you threw yourself headlong into AI?

Marie-Alice: That’s a very good question. So I have a dev profile. I’ve been doing dev for 15 years. Before being an AI engineer, I was a dev. That’s for sure the most important thing. I was simply in the right place at the right time when generative AI (GenAI) appeared. At the time, I was in a small AI R&D team, so I was in the middle of data scientists as a software engineer. And then generative AI is clearly the intersection of data science with dev. For me, that’s what I experience on a daily basis, and so I was able to be in the right place to be at the intersection of these two fields.

Raphaël: Cool. So why I became interested in this subject is because I, by dint of analyzing the weak signals, or not weak ones for that matter, that we see emerging on social networks and in open source ecosystems, I realized that AI still had a lot of impact on open source projects and communities.

In fact, AI has gone from… first, when we talk about development, coding assistants who are there to help with completion or propose code snippets, and then the more it goes, the more we go towards agentic development where we actually delegate complete parts of the implementation to agents.

And the central question that this led me to ask myself is: is generative AI (GenAI) just a tool that is useful and that just accelerates the work of developers, when you see it from a really everyday use point of view, or is it not having a very powerful and important impact on the very foundations of open source? And that’s what I developed in my conference. First of all, do you make the same observation in fact, quite simply?

Marie-Alice: I agree with you. I’ve seen several times on the networks, on LinkedIn, etc., people who said: “Well, we’re overwhelmed by pull requests generated by AI, which have neither head nor tail, and that we can’t see again. And we’re going to stop, we’re going to block all this because we can’t manage it. »

On the other hand, I have two things… To give a little bit of context, I’m a fan of home automation, so I have a home automation system that I tinker with myself, which is based on Home Assistant, an open source solution. So there’s a part that is paid, but the core is open source. And I’ve contributed to two things.

In any case, I tried. The first one was a small front-end bug. So that’s something that was quite easy to manage, but I absolutely wouldn’t have had the time to do it normally if I hadn’t had the AI, because the front-end is not my expertise. I could see the bug very well, a problem with the ID of two components that had the same ID. If I hadn’t had the AI, I would have spent too much time reading, the syntax, I didn’t know it well, it wasn’t my language that I use on a daily basis, etc.

So that, for me, was so easy. I opened the PR in two minutes, it was merged, integrated and deployed on the other side just as easily. And then I made another contribution on a much more complex subject. And there, things get tricky. Maybe I can talk about it later.

Raphaël: Okay. And on this first contribution, so it means that the AI helped you understand… because the bug you say you had already identified it in fact?

Marie-Alice: Yes, that’s right. In fact, it’s a classic front bug: you have a page with three buttons, you click on the first one and it’s the animation of the third that is triggered. When I saw that, I knew very well what was going on: the three buttons had the same ID and therefore the animation was going badly. So that’s a little fix.

Raphaël: Okay. So this first contribution you made to Home Assistant, in fact it accelerated you, but you’re in “I’m actually contributing a patch, I identify a bug, I’m fixing it” mode.

And in fact, that’s kind of how contributions to open source projects have been done historically: it’s brick by brick, there are people who join a community, they identify a bug, or even they fix the doc, etc., and then there’s a relationship of trust that is made with a human, and with other humans on the other side, people who review the code and who will do the MR [Merge Request, also called Pull Request].

After today, AI allows you to go much further, especially if you go into agent mode. And sometimes it’s more than contributing a brick, it contributes a wall, or even a house. And that’s much heavier to manage on the project side. I don’t know if you’ve observed that, or if even your second example goes more in that direction?

Marie-Alice: yes, I think so. So my second contribution is more about a key feature at the heart of the system. And so clearly, I have to be able to integrate into the community. I’ve talked a lot with people on the discussion forums related to the subject, otherwise it’s impossible to have a PR that is integrated. Of course, I have to show that I’ve studied the subject. There, it really becomes a human exchange that is much more complex because the issue is complex.

Raphaël: Okay. And so it really touches, as you say, at the heart of the matter. Was your MR finally integrated?

Marie-Alice: No, exactly! So that’s another point. The first version I made, I opened the first PR in February, and so it’s still not integrated, it’s still under discussion. And really what I see and what I feel is that in fact they’re overwhelmed with PR.

And as much as I feel able to understand the code, to be able to make changes and propose changes to the community, I don’t feel legitimate to review other PRs. So that’s what is required. So when we open a PR now, in fact we have a small checklist of things to check before opening a PR, and among this checklist there is: “review other people’s PRs”. And finally I find that positive, it’s a very good idea. On the other hand, it’s much harder to do I think.

Raphaël: Oh yes, it’s really very interesting in fact this system to redistribute the workload, because as you said, what you sense and we see it, there are plenty of projects that complain, that are overwhelmed with PR.

The difficulty of producing the code and contributing to the project, the difficulty of contributing has moved with the AI. Before, it was the developer who spent time, who said to himself “but am I doing the right thing?”, he discussed like you do here with people or not, but in any case at the level of the code he did it with great care, and then he proposed the PR, and then there was a discussion etc.

Today, the implementation phase can be extremely fast, or even done by someone who really doesn’t understand, even less than you, that is to say who doesn’t understand the thing, who is almost someone who is looking to contribute to an open source project because it’s cool! And as a result, projects are completely overwhelmed with PR, and so all the effort is transferred to the review part, code review.

And it’s true that I find it super weird to say: “Well, we have to participate in the war effort.” And the war effort is more about the code. In fact, what it proves to me is that the war effort now is: help us make PRs, because that’s where we need help. Of course we want code, but code is coming like a tsunami to us. And we have examples of projects that have stopped bug bounties.

I was talking about it with curl, I was rereading an article written by the maintainer of curl, he said that at one point his wife wondered about his health in fact, he was working so much. He says: “I’ve always worked a lot, I had a balance between my public life and my personal life, and then my wife started to say no, now it’s not okay, you work hours and everything, it’s not going well at all.”

And so they stopped the bug bounty for example, because there were too many contributions. So it’s true that it’s not bad this thing to come back. But suddenly, for you yes it puts you in a situation where you want to contribute, you feel that it brings something since it touches the heart, but for all that you find yourself in a complicated situation. Why? Because it would take too long to get into it or…?

Marie-Alice: As much as the feature I wanted to implement and push into the project, I dug into it thoroughly, so I’m able to discuss it. So I don’t know everything, plus there’s a pretty complex story, a story of specifications, standards etc., but I’ve dug into the subject enough, partly with the help of AI, to get opinions on the question, or on the questions. And reviewing PRs on other topics would be much more complicated for me. It’s a huge project, there are a lot of parts of the project’s code that I don’t know. That’s it.

Walid: What I find interesting about this is that you have projects that, in the face of the arrival of AI, put a code of conduct where they say “we don’t want AI”.

There are others where it’s still a bit unclear. So I don’t know in the case of Home Assistant, do they have a charter? How did they do it? But for example, could the rather ingenious way of doing things that they put in place encourage you, for example, to say to yourself: “Well, finally the subject is interesting, I’m going to take some time to get into the subject and even if, why not, become a more occasional contributor, but a contributor to the project.” Didn’t they finally turn the situation around in a way?

Marie-Alice: yes, yes completely. Of course, I think I’d be able to have opinions on this protocol. I’m working on the integration of a particular protocol, and so now that I’ve delved into this subject, I think I’ll be able to have discussions on that point. On the other parts of the project, no.

But for sure it allows me to get into it, in fact it’s like any other dev project: when you arrive in a new project with a code base that’s huge, having an AI assistant that allows you to scan the code, to tell you “this is this feature, it’s going to go to such and such a place, you can look at this piece of code there to better understand what’s going on”, in fact it helps a lot.

Walid: And they have an AI charter?

Marie-Alice: So, I’d have to look to be sure, otherwise I’m going to talk nonsense. There’s no AI refusal in any case. My PR has been reviewed by a bot by the way.

[AI charter of the Home Assistant project]

Walid: Okay.

Raphaël: yes, it’s very interesting. I was looking to see if there was a charter, but well, we’ll look at it later, post-recording, we’ll put you the links if it’s necessary. yes, what’s interesting is that you said, in fact home automation you’re passionate about. That is to say, if you implemented this protocol, it’s because you needed it and you said to yourself…

That’s what pushes people to contribute to open source projects at the base. And the reflex you had, I personally think it’s great, is that right away you started talking to people upstream. But today, when you say PR is still under discussion, does it continue to discuss or is it just that they don’t have time and they left it a little on the side?

Marie-Alice: Clearly both. Clearly both. It’s been several years, so what I’ve done, I’ve been finding feature requests for it for several years. So it’s not just my need, it’s something that has been requested and re-requested for a long time.

I’ll give details, maybe it will be easier: it’s a homemade alarm system. I bought a small box that allows you to make a code and put an alarm in the house. What wasn’t supported was the delay when you activate the alarm, there is a small delay when you lock the door and get out. The small box is able to make a small continuous beep to say: “Be careful, there’s a little beep beep, hurry up, then it’ll ring.”

In fact, it was the small delay that wasn’t supported. So they made Alexa pass the little beep, and Alexa, for example, did the countdown. So a workaround, but it’s a real shame. The small alarm box, I think it’s the most expensive module in my entire installation. After that, I only have small things that cost a few euros on doors and windows. So this big thing is the most expensive thing I’ve bought, and there were only 50% of the features that were supported. So for me it was inconceivable.

If I hadn’t had AI, I would have been unable to understand what was going on, find the right place in the code, etc. Well, with a full-time job anyway, it’s impossible.

So that allowed me to contribute. And so, my PR still hasn’t been merged, but my patch is on my installation and so at home it’s been working since February. So at least that’s already for me, it’s a big victory.

Raphaël: And the fact that it’s not merged, as I was telling you, is it because they don’t have time to take care of it anymore or do they take time to understand? In fact, because you know there’s this notion of understanding tax. That is to say that you spent time on it, you had the AI to help you etc. Now you’re telling me that there is still an AI that has made a first filter, that’s also interesting what is put in place on the projects. But maybe it also takes time to understand the code and to understand why it’s OK in fact?

Marie-Alice: yes, but I also think there’s still a question of time in general. Because you see, there are people who have commented on my PR by tagging other people who are also core contributors, and those people haven’t responded. And I think they’re overwhelmed actually. That’s it. So I think there’s also a question of time.

Raphaël: We’re right in the same thing I’m observing, that’s really it. In fact today projects are under pressure and the core contributors, the reviewers, they don’t know how to manage anymore. So there are some who ban AI outright now. So it can be for reasons not only operational, maybe it’s philosophical, I don’t know.

But it’s true that it has a strong impact today on communities and on their governance in fact. Little by little it’s getting organized. But I think it’s a good idea to turn the tide. But you precisely, the way you’ve used AI, you’re an AI engineer, you’ve been immersed in AI for years, you write books on it and everything, this notion of AI slop, what do you think of it?

I like how they say in Quebec, they talk about degenerative AI. But how do you make sure that your agent or everything that you are going to produce with AI, or that you are going to delegate to AI, isn’t that right?

Marie-Alice: I think it’s very, very complicated. As much as on the forehead part, the little fix, there I have no problem to reread and understand what happened. That’s it, I’m 100% sure of my PR. On the complex part, I had my doubts.

There were things where I wasn’t 100% sure. It seemed pretty good to me, it worked, I understood how it worked, but I wasn’t 100% sure that it was the best way to do it. It’s my basic job to do dev. It’s so easy now to do PR.

It took me a lot of time to reread, iterate with generative AI to have something that works and of quality that seems pretty good to me. I think on something as complex, AI needs to be guided. Of course, otherwise it would be nonsense.

Walid: One of the criticisms that can also be made by maintainers is that people don’t necessarily indicate that it was done with AI. How did you in your case put forward when you made your pull request, how you highlighted at what level AI helped you, the uncertainties you have etc. ? Is this something you put forward when you proposed?

Marie-Alice: I don’t think I highlighted my uncertainties about AI. On the other hand, I explained in detail what I had done, to say: “I took this hypothesis, I did it like this, and like this, and like that”, so that it would be easy to reread and so that people could give an opinion.

yes, that’s a good question. I don’t think I consciously wanted to hide the fact that I had used AI. I think it’s pretty obvious and quite widespread. On the other hand, would I have… I don’t know, maybe having explicitly put “I used AI”, it might have done me a disservice. Because when you arrive in a new community, people don’t know me, they don’t know that it’s my job to be a dev. And if I put “I did this with AI”, people, at least in the place of the maintainer, I would have said to myself: “Oh my, what’s this thing?” I don’t know!

Walid: No, no, but that’s what’s interesting. There are communities in which… I don’t remember which conference, the maintainer said: “Well, it’s easy to understand when a pull request has been made by the AI. You look at the text, if it’s written in too good English and it’s too polite and everything, it’s AI, you know. ».

To which you can say: “Well, in fact, you take a person who doesn’t speak English well, who made his own pull request, who helped himself to make the text of his pull request with AI, it goes into it. So nothing is black or white, you know. »

Marie-Alice: yes. I also think… Well, it’s not related to open source, but to development in general. Rejecting AI outright, I think it’s going to lead nowhere actually. Now we’re at model performance levels that make it no longer possible to say: “I only code by hand, I don’t do AI at all anymore.”

The problem with open source is that we’re not in classic dev, we’re in a project that everyone can contribute to. Everyone has different profiles, different levels of skills in the dev. And I think that’s where it’s much more difficult to guarantee that the person who wrote the code understood what they were doing.

Raphaël: Because what you did to explain where you had gone etc. Before, these are things that some projects require. Typically, they say: “No PR if it’s not associated with an exit that has been opened before and that explains why and how in fact, in your own words.” And indeed there is this project, I don’t know what it is, which said: “In your own words, and to bounce back on what you were saying Walid, if it’s AI we’ll see it.” But indeed it poses the problem of: yes but it’s a barrier to entry anyway, the mastery of the English language for some, you know.

Marie-Alice: Yes, and then “if it’s AI we’ll see it”, okay, but in fact I’m convinced that in the future development will be more than AI anyway, so that’s what’s complicated.

Raphaël: Yes, indeed. But it raises a question by the way… Well, on Home Assistant it’s a big project, but we’ve seen several projects that have been reimplemented from scratch because today with the right model and the right harness, we’re able to really generate things quickly, especially if it’s framed.

And there was this example of a project, I think it was chardet, where the license was problematic because it’s LGPL and therefore it means that there is a copyleft part in the license. If you don’t use it via the APIs as it was intended for, but you link with the code differently, then the code can be contaminated if you see it negatively by the copyleft aspect.

FOSDEM 2026 conference that launched the concept of Clean room as a service

And so someone said, “Well, reimplement me from scratch, you know.” And he put it under a permissive license. And that’s a problem because when the community reacted by saying, “Wait, there’s plagiarism actually,” he said, “Well, no, look, when I compare the codebase, it’s 1.3% similarity.” So the notion of plagiarism itself is called into question in this story.

And that’s why it’s interesting to watch because it really shakes up the fundamentals in open source communities. Obviously it doesn’t start to reimplement the same codebase directly, but at the base he still asked his agent to reimplement chardet.

So that means that the agent knows the code of chardet, it’s part of his training data. And then overall all these models were trained on a lot of code that was available, so that is to say open source. Maybe by being a little not too careful about licenses or how it is used. I don’t know what you think about it, because you say that you also use it a lot in the dev. So it asks the question the other way around too: when you develop and everything, how do you feel in relation to: well, we’re perfect with these notions of plagiarism…?

Marie-Alice: yes, I don’t have a good answer on that. When we worked together a few years ago, at the very beginning of code assistants, I did, I don’t know if you remember, but at that time I had done a benchmark on all the programming assistants on the market.

And I had made a selection in relation to that, and I had eliminated some of them in the proposal I had made to our company. And in the end, this is not the criterion that was retained. And we didn’t go for the assistant that was the most regular. But it’s valid for all companies today: those that are market leaders there, it’s not the ones that are the most regular, that respect open source, you know. So I don’t have a good answer… It’s… I don’t have a good answer on that, you know.

Walid: It’s a bit like the Wild West, eh.

Marie-Alice: yes, that’s right.

Raphaël: Yes, it’s the Wild West, we’re in an area that is not yet fully explored, it’s the case to say so. And it moves so fast! But then it’s sure that the most powerful models a priori, in addition to the computing power, well that’s you the engineer who will confirm this for us, well there’s also the data. So it’s sure that it’s also those who have had more data to train, regardless of the precision and the power that is put into the training.

Marie-Alice: Yes, absolutely. And we can see that in fact, this is the example I just gave, people ultimately what matters to them is that the model works, and that it is the most powerful, the most… that’s it, these are the ones that work best. And the criterion of: has it scraped any rest that they shouldn’t have, that comes later.

Walid: It raises questions… Well, I think the technology is beautiful, but I’m extremely, extremely critical of the industry. And I think it’s the total Wild West and it’s the negation of a lot of things. Because in the end, what’s the point of you spending time, what’s the point of us spending time making podcasts if in any case the thing is going to be completely scrapped, reused without any of our agreements, nothing at all? And what’s the point of making code…

Finally there is a real question in my opinion who is behind this, which is: what is the point of making open source code if in any case this code is going to be taken, reused, if on top of that you can finally do without all the collaborative work of people because you just don’t agree with the license that people put and you reimplement the thing and you do your thing behind it? In the end what is left of that, and finally is the…

Some time ago, there were people from Cal.com who said: “yes, well finally because of AI we’re going to close our code.” Well, when you dig a little deeper, that’s not exactly what happened, it’s more of… AI seems to be more of an excuse. As I was talking about just before, the fact that equipment manufacturers are increasing their prices, of course AI has something to do with it, but they also took the opportunity to increase their margins a little bit too.

So AI is for that, but it raises questions about: what’s the point of putting open source code if in any case the big manufacturers and big model sellers don’t give a damn about licenses and nothing, they stole all human knowledge and then afterwards they make you pay? So it raises questions and I myself wonder: is it worth it to make open source code in the end, if you go a little bit to the end?

Raphaël: Ah, it’s sure that it’s stirring up the fundamentals there! That’s clear. There’s another question I ask myself, but you see on a project like Home Assistant it’s so big that in a pinch you didn’t have this reflex to say: “Well, I’m going to make my own Home Assistant, we optimize everything, we reimplement in Rust, in Zig or I don’t know what language”, you know.

But there’s this notion that I see emerging called “selfware” in fact, where, as it’s possible, there are people who make their own software and then in fact there’s no community anymore. That is to say: why bother me by going to do what you did there, going to discuss, explaining, and then waiting, being patient, saying “well then, are you sure?” etc., when I can do my thing in my corner with a great agent that I even run now in loop engineering , with the new types of models, the new ways of working.

In the end, there’s no need to collaborate with humans anymore, I collaborate with my agent. I don’t know if you see trends like that…?

Marie-Alice: I don’t know. I still have the impression that for most people who are in dev, what they also like is the challenges and the community. I’ve met very few… well in my whole career I’ve met very few devs who didn’t like to share their code with others, who didn’t like to explain their ideas, who didn’t like to defend their position vis-à-vis others.

Even if we have the impression that dev is a job that is quite solitary because we are each in our own computer, we are each in our own code, for me it’s something that is very collaborative in nature. And I have the impression that most people are in that state of mind. So maybe it’s optimistic. Of course, that doesn’t prevent people from saying: “No, I’m doing my thing in my corner and it’s working, and too bad for the others.” In fact, what I could have done!

I could have very well patched my system, kept it to myself and it works, and then I don’t bother doing PRs, talking to people and that’s it. But I think that’s… Maybe AI exacerbates or highlights these behaviors, but I don’t think it changes… that there is a real change on that. It’s, let’s say, it’s not a statistical study, it’s a 100% personal feeling!

Raphaël: Anyway, I don’t think we really have good visibility. As Walid says, we’re a bit in the transformation zone of all this, it’s difficult to take a step back and see clearly.

In fact, what I tell myself is that AI accelerates. So it accelerates everything: it accelerates good behavior, it accelerates bad behavior, it accelerates AI slops, it accelerates the right way to contribute to the project. And from this point of view, it’s perhaps an opportunity to realize certain things that we didn’t necessarily see because it took time, now it can be seen very quickly.

So it’s true that it can be scary, but at the same time it’s a good mirror to look at how communities work, how people are… what are their postures towards these communities or towards the code in general.

Walid: Where it makes a change potentially… For example, I see around me, if there’s one thing that everyone vibes codes and redoes in their corner, it’s a monitoring tool. Before what would you have done?

Before you would have looked at what monitoring tools existed, either you would have taken a SaaS service, or you would have taken an open source tool, maybe you would have paid for that tool, maybe if you were a dev you would have tried to contribute. And then, around me everyone recreated their monitoring tool. They are all great, but they are all different.

And finally on a very specific case like that, which is personal where you tell yourself that there is not much impact on others, well finally the developers who were doing their monitoring tool in their corner, well their monitoring tool that they were selling or the open source product, they potentially have fewer customers tomorrow because people will have recoded their tool themselves.

And then, at the same time you make your tool for yourself and that’s great, and I’ve seen some really great things from my colleagues, really very good things; at the same time you don’t pool on these needs anymore, in the end. So we’re going to win on one side, and we’re going to lose on the other, a bit like for many other things. I don’t know what your opinion is on the matter.

Marie-Alice: It’s true that there is less perhaps… that there is less of this need to collaborate. That everyone can be self-sufficient.

In the end, it’s with AI that we collaborate, that we exchange ideas and we may have less need to work with our colleagues. It makes me think… it’s not related to open source, but it reminds me a bit of the fashion we see on social networks, especially LinkedIn, where people say: “Now with AI you can create 5 SaaS a day and you’re going to become super rich.” yes, but it’s not because we do times 5 on the number of SaaS or times 10 that customers will also do times 10 and that suddenly people will have times 10 to spend.

It’s not because we create things that there are necessarily people who are ready to buy it.

Raphaël: yes, because we’ve been talking about collaboration since earlier, but in fact the issue, I have the impression, for communities in terms of governance… In fact, historically, we had a README.md or a CONTRIBUTING.md that was aimed at humans.

And we would say: “Well, if you want to contribute to the project, here are the rules, here is the governance.” Then there were even the codes of conduct, and then we asked humans to get involved. So there is a social or moral contract when you contribute to the project, but sometimes it’s the same: I give up rights, so there are the DCOs, there are documents that you have to sign, or at least that you have to have targeted. But now the challenge is: as there are going to be more and more agents, in fact we have to integrate the agents into this governance.

And so maybe you can tell us what you see. I saw that there were things like de facto standards that emerge like AGENTS.md, I don’t know what you think?

Marie-Alice: yes, I agree 100% with that approach. I think that saying “no, we want more AI”, well “we want to block AI in open source projects”, I think it’s going to hit the wall. I’m much more in favor of putting a AGENTS.md, even README in fact. In fact, everything that is README etc., it’s going to be read by humans.

In fact, anything that is readable by humans, it works very well for agents too. So if the project was well documented at the base for humans, for human contributors, it will also work for agents.

But even more, yes, adding AGENTS.md, I think that’s a better approach than saying “no, we don’t want AI”. I think that’s shooting yourself in the foot and going against the direction of travel. I think it’s inevitable, and now we just have to take advantage of it, make it positive rather than hide from it and say, “No no no, we don’t want AI.”

Raphaël: The thing is that as it goes fast and the impact is strong, it’s true that it shakes up habits a bit. And we saw what we said at the beginning of our discussion, some kind of burn-out that can happen at the level of maintainers. They have a hard time taking a step back and they continue to work in the classic way, in quotation marks, where they validate the PRs one by one etc. There you said that there was a bot that had finally passed, which had done a first screening I think of your contribution. Do you think that this is a direction, to also use AI to help manage this?

Marie-Alice: yes, completely. I think it’s impossible to go at the same speed… Precisely, if you code with AI, you code 10 times faster. I’m caricaturing, but let’s say that’s the number. If we don’t have something in front of us that is also 10 times, well the reviewers will be completely overwhelmed. We can’t say we code differently, but we continue to do reviews in the same way. It can’t work in fact. So clearly we have to adapt the process to the whole chain and not just to the part where we code.

Raphaël: But in what you’re saying, does it mean that the point of containment, the bottleneck, is still the human? But if we say: we want to remove it on the whole chain, does that mean we actually remove the human?

Marie-Alice: I don’t agree with that. I think that a bot that reviews a PR already allows you to do a first analysis, it allows you to remove certain bugs or not. Me, the bot… there are things that the bot has noted on my PR, especially by comparing it with the spec, with the standard.

And I hadn’t seen that. There are things I hadn’t seen, I hadn’t found that paragraph in the norm, and what I had done was indeed not quite coherent. But if I followed the norm, it didn’t work! Because the seller of the physical keypad there, he hadn’t respected the norm either and in fact that’s it.

There are things like that that raise points of discussion. So I was able to argue, I was able to explain why I did this, without having a human… It would have been much more complicated to say: “Oh yes so this…” In fact, there’s no point in it not being done by the AI. To say “this affects such and such a place in the spec”, the bot looks at the spec, it compares and it says: “Well no, there’s a diff.” That’s typically an AI use case that’s very good.

Raphaël: yes, okay. So automating what is really basic and where there is no human added value. So the human added value moves.

Marie-Alice: Yes.

Walid: But what is the role of the reviewer then? The role of the reviewer is to look at the integration into the technical architecture?

Marie-Alice: yes, for me that’s right. But then, once again, I think it’s not limited to open source, for the dev in general. I think that clearly we move from code technician to architect and code designer . On my PR for example, there was a debate on: should the functionality be global or by zone? And that’s an architecture debate that the bot didn’t have. And so that’s a debate that happens between humans.

Walid: And given the number of data, the number of debates that the bot will have, tomorrow the bot will be able to do this work. I don’t know, my understanding is that tomorrow if you give it a lot of data, it will at least be able to make you recommendations that you follow or not. And so the question, for me I don’t have the answer, I don’t know at all, is: does the place of the human tend to remain only at the top of the spectrum and everything else will be automated, or does the human still have a vocation to keep a fairly preponderant place in a large part of the chain?

Marie-Alice: In my opinion, the place moves, the value of the human moves. I was talking about code on a project in general: I have a bug, I ask the AI to fix it, to help me.

And in fact what will happen is that the AI will see the bug and fix it in a local place. I review what it does, I say to myself: “But actually no, it’s not good, we should have done a middleware, corrected in a more global way, etc.” And that’s a vision today that I can’t achieve… Well, it’s my added value that for the moment I don’t see in AI.

When I give her the instruction, she tells me: “Well, in the end, I prefer it to be done like this”, she writes me the middleware and it’s done. And for me, that’s much faster and I have bother… I didn’t bother working on the technical details, but I was able to give a direction that makes my project much more maintainable and voilà, have a better architecture. But that’s a debate on the place of the dev in the years to come, in the months to come.

Will AI one day be able to have this vision, the overall vision and make architectural choices in a global way? Today I want to say no. But it’s going so fast that for me it’s impossible to predict. And then we come to the question: are we all going to be replaced and will we have… Will there still be people who do dev in general? But hey.

Raphaël: But in any case, so now I’m putting on my architect’s hat, because we were talking about AGENTS.md to guide the AI, but it’s more about telling it “this is how you do it, this is how you test, this is how the repo is organized, the rules in terms of interaction with the subject”. But we can go further actually…

We can guide AI on the architecture itself… because in projects, it depends on the maturity of the projects, but sometimes the architecture is not explicit, it is not described, the architecture rules are not easy to find, if they are documented. Whereas with AI, it is good for reading documents.

So it pushes humans to ask themselves the question: “Well, what am I doing, how am I doing it?”, so asking themselves questions about architecture. And with the notions of ADR (Architecture Decision Records), I don’t know if you know or if you already use it, you may give us a feedback on this, on the Architecture Decision Records, to trace the architectural choices: when it was made, what was the context, what were the pros and cons of this decision, what are the impacts that we anticipate, to be able to keep track and the history of the architectural decisions.

And it, the AI, will be even stronger than us in integrating a set of ADRs that correspond to the history of the project or the current situation. It may also be a way of guiding the AI, but always by leaving humans in charge.

Walid: I would like to come back to a point we were talking about: the fact of saying, so there are open source projects, I know quite a few, that completely reject AI outright. I would like to come back to this because I have thought about the question quite a bit, and the question I ask myself is: one, does this mean that globally their community will eventually reduce?

And two also, from the moment we have models that are always more powerful at finding flaws, if you refuse the AI en bloc and therefore refuse yourself to use tools that will allow you to find these flaws, won’t people finally stop using your tools because they are insecure?

I’d like your opinion on this because I understand quite philosophically that we don’t want to use AI and have to deal with it, but in the end in reality you suffer something that is beyond you, which is that if the tools can find flaws in 3 seconds and the person who tries to correct them, he says that he found them with an AI tool and that people refuse the thing because the AI was used in the process, in the end isn’t the system counterproductive?

Raphaël: Okay, so I’ll give my first answer: security is also a real impact of AI, completely. Everything we were saying there, overwhelming tsunamis of PR and everything, so in terms of security it’s the same. The example I gave of curl was that, bug bounties. There are others who have stopped bug bounty because with bug bounty what do you say?

You say, “I’ll give you a little bit of money if you can find a way for me.” Well, the motivation goes up like that, how easy it is. That’s the first point, that’s the human part.

Then there is the part of the models themselves. We can see it now, the border models, the most powerful, they are becoming geopolitical objects. Finally, when it comes to deterrent weapons, it’s starting to become complex.

So I don’t know what you think about it by the way, is this a bit of a political or geopolitical recuperation of all this, or should the AI actually be left in the hands of a few good people who we have to trust, because they are so powerful and that it can allow you to enter the NSA like that by snapping your fingers?

There may be a lot of movement around it, but it’s sure that it still raises the question you were asking Walid: but if in terms of security it’s as powerful as that, should we ignore it or not, what? Well, I asked a lot of questions at the same time.

Marie-Alice: I’ll try to take them in order. So already for the bug bounty, in fact the bug bounties they rewarded an effort. Let’s say that the reward was equal to the effort. Now the effort with the AI is almost zero, it’s normal that the bug bounties are almost zero too. That doesn’t seem shocking to me, it seems to me a natural evolution and a natural adaptation: effort – reward.

Then, for the security issues and how the models would be a danger to safety, I think that there is still much more politics and marketing in this story than rational and technical. Models that are not currently blocked also find a lot of security flaws, we don’t need Fable and Mythos for that.

So I think they just… That’s it, it’s more powerful, etc. I think that it’s mostly a marketing stunt that has unfortunately backfired on them. We’ll see what happens in the coming weeks. Then, keeping it in the hands of a few, that’s a debate that’s really complicated.

Because how do we choose the few? In today’s capitalist world, we know very well that in reality what will happen is that it will be in the hands of those who have the most money. And whether these are the people who really deserve it or in whom we should have the most confidence, I’m not sure.

It reminds me a little bit of 3D printing a few years ago. I don’t know if you remember, there were people who had made weapon printing models with 3D. And similarly, there was a big debate about: what do we prohibit, what do we do, how do we regulate? I don’t think there was a solution.

I don’t actually think that it has been resolved. I think it’s just that we stopped talking about it, but I think the problem is still there. And in my opinion it will stay that way for AI as well. I think we… I see right now, I can’t find good regulation solutions without the one with the most money getting the tool. Maybe I’m a little cynical, I don’t know what you think.

Raphaël: Well, let’s say that today we’re in the middle of the… well the ford… I don’t know if there’s a ford actually, because the ford is like you cross a river and everything, maybe it’s a bit of a big river actually, with lots of currents in all directions.

It’s true that it’s hard to see where we’re going, because the technology itself is not stabilized. It continues to evolve and so the impacts are enormous, and on top of that there is all the discourse that will be raised on top of it because there are political and geopolitical aspects that are grafted onto it.

So it’s true that it’s a little difficult to see clearly and that’s where we can very quickly get scared, or conversely be very excited by saying: “Wow, we’re going to invent a lot of new things, yes well it takes a little time, we’ll adapt, but it’s going to bring us to a new state, a new stage and we’re going to go up in abstraction in fact.”

If I go back to development and what we were saying: we’re going to do more architecture and fewer syntax bugs, or learn the syntax of this other language. Well, it’s true that there’s this subject. But if I come back to your subject Walid, projects that prohibit any AI contribution, it’s the case of Zig which is a not very well known programming language. And Bun, the JavaScript engine, was written in Zig historically. And the leader, the author of Bun, wanted to use AI and so he was annoyed about this Zig thing. So it corresponds about the time he got hired by Anthropic too.

Walid: Yes, that’s right.

Raphaël: So he got hired by Anthropic, so he doesn’t have a problem with tokens, that’s for sure! It’s open tokens, it’s like the open bar. So it’s sure that they show us the ideal use of AI, it’s open bar. Well he decided to reimplement his own project in Rust.

So that’s what we… That’s the example I gave earlier of saying “yes but where is the limit of plagiarism?” Well, that’s his project, he does what he wants. And he reimplemented it in Rust because he wanted to depend more on Zig who was anti-AI. The thing is that right after that, Anthropic announced, so I don’t know what it’s called, Dynamic Workflows I think. Basically, we see that these actors, they are also trying to control the whole chain, and we can understand that, and therefore the execution as well.

So having Bun who is in the sphere and in the Anthropic ecosystem to be able to execute swarms of agents, tomorrow who will clone themselves or dispatch themselves like this on infrastructures and then be able to carry out things in an even more autonomous and even more self-organized way, well it makes me think of the fact that yes, the AI is expanding horizontally, but it is also moving vertically. It is going down a little in the lower layers with runtimes. I don’t know if it makes you think of things, you on your side, what you already think about it? Have you observed this phenomenon?

Marie-Alice: It doesn’t surprise me at all actually. For me, it really goes in the direction of: banning AI is going to the wall. For open source, the problem is this: it’s that it’s amplified by the fact that everyone can contribute, that there is no barrier to entry. When you’re in a company, in fact, you have people who contribute to my project, they’ve been recruited, they’ve passed technical tests, I know them, there’s a kind of guarantee of their skills.

Whether they use AI well or not, we’ll say that it’s okay… it doesn’t fundamentally change how we work in a company. For open source, the barrier of entry no longer exists and as a result it’s much more complicated to manage. I think the big difference is there compared to corporate development. And there I got lost in your question!

Raphaël: My question was the fact that… So yes great, this notion of trust in fact. The contract of trust which is difficult to maintain in this case. Especially when the developer is only a proxy in relation to the agent and in the end he doesn’t understand anything, so in fact the trust is no longer there.

My question was: what do you think of the fact that these ecosystems, these platforms, they are becoming a bit hegemonic and also going down the layers and towards the runtimes ? I say to myself: at some point, if we start to look at code too much, is code something that remains for humans in fact?

Marie-Alice: yes, that’s 100%. I totally agree with you. Clearly, the code we write, the comments, etc., are made to be read by humans. AI wouldn’t need all the standards we have at all, to put comments, to write explicit function names, etc. AI could manage otherwise, or even invent its own language that is incomprehensible to humans.

In theory. In practice, in fact, how does AI work, why is AI so strong, it’s because it has read code for humans. AI would have to invent its own language, train on it… Today it’s not the case actually, it’s not possible. We don’t have a… Anyway, why my AI is so strong when I do Python is because it has read tens and thousands of Python reposes.

She’s not going to suddenly create her language and be as strong in a language that’s as relevant. That’s what I mean. So, in theory, I totally agree that we can very well do without what we have today that is actually made for humans. In practice, we don’t have a training base for models that isn’t made for humans. Maybe it will come in the future. But today it’s not the case.

Raphaël: yes, so it’s really the training data, we come back to that. And it’s thanks to all the comments that there are in all open source projects that, when the AI (GenAI) produces code, it will naturally also produce as you said variable names, function names that are explicit and it will put comments because that’s what it was taught.

Marie-Alice: I don’t know if you’ve seen any kind of experiment where there are people who said: “Yes, I had two AIs talk together and then they started talking with beeps and suddenly I couldn’t understand what was going on. In short”. Well, in fact that’s! It’s in the instructions of the AIs to start talking with beeps. It’s not something that appears naturally, that’s it. That’s just that it keeps our imagination going.

In fact, it fits with the image of AI in science fiction and so we tend to encourage it, either to create a buzz, or because it’s our way of thinking and we project it onto AI.

Raphaël: yes, so there are a lot of fears and uncertainties. So we fill the spaces with what we want.

Walid: Wait, there are a lot of fears… I’m going to make a reference to… It’s not me who found this, well who’s talking about this, it’s the Radio-Canada Décrypteurs podcast, which is a source that I follow all the time and which said: it’s still weird because an industry normally tries to sell you something sexy that makes you want to. Why does the AI industry sell you fear? I don’t have the answer to that, but why are they selling you fear in fact?

Marie-Alice: Who are they selling fear to? We’re afraid because we’re at the bottom of the chain, in quotation marks. But those who have a lot of money, to whom we say “but in fact tomorrow you’re going to be able to fire thousands and thousands of devs and you’re going to be able to save a lot of money”, well no, they’re not afraid! You see, I don’t know how to put it. Maybe, again, it’s a bit cynical, but I think we’re scared because we’re in the wrong place. If we were millionaires and we could buy all the tokens in the world to do what we wanted, well we wouldn’t be afraid.

Raphaël: You mean that we’re not the customers actually?

Marie-Alice: yes, to sum up.

Raphaël: We’re a side-product, yes okay.

Walid: But on the other hand, what I find interesting is… I had the impression that the system was indeed putting the load on the maintainers and that finally the maintainer sees a pull request, he would almost have done it faster to do it himself with AI and get the result he wanted.

And so that collaboration with the people who send him code, in the end it’s almost pointless. The example you gave with Home Assistant seems really clever to me, to force you to enter the project and review pull requests and everything. For the time being, that’s interesting and it gives a little hope on the fact that, maybe, you can find clever ways…

Well, it’s not the first threat that open source has seen and it has adapted. The question is rather the speed at which all this happens, but there may indeed be people who have interesting ways to turn the system around and make something interesting out of it.

Raphaël: Yes, we see some interesting stuff. We talked about AGENTS.md, there are people who are doing no-AGENTS.md. No-AGENTS.md it’s… so it can be “we don’t want AI at all”, but it can be “we don’t want AI everywhere” too.

And that can be interesting to say: this is the heart of the system, we want to keep control of it. Here we are, as you said, on the front end, etc., we don’t have a problem with the fact that AI is used. Or it can be other choices, but manage to have a finer posture, not all black and white. I think it pushes us to ask ourselves good questions also in terms of the project, and again in terms of architecture.

We also have people who do HOWTOAI, HOWTOAI.md, it’s more for humans who use agents. Say what do we authorize you to do. In fact, it’s the social contract that we want to put back and that we want to make explicit. And that’s why I say that AI (GenAI) pushes us to update the governance of communities, of projects, by making the thing explicit.

Because as you said Marie-Alice, the AI reads everything, so it could understand just the README. But to have really specific, very clear, very well identified, even a little standardized, standardized parts so that the agents can really take it as instructions, it can be… In any case, I see a lot of projects that are starting to do this kind of thing.

Marie-Alice: On the AGENTS.md, I would just put a very small limitation: it’s that you shouldn’t fall too much into the trap of “we generate it by AI”. Because here it’s the snake that bites its own tail in fact. Because the AI will put instructions that it already knows, so in the end it’s useless because it would have followed them naturally.

So it’s a useless use of tokens, you know. I think the AGENTS.md, we have the impression that having something very long, very complete, etc., is going to be more efficient, more powerful. I think that very often we can do something much simpler and much shorter, with instructions that are specific to the project and not just general good practices that the AI knows anyway. There you go, we have something that could be more efficient.

Raphaël: yes, so as not to exaggerate the context in an unnecessary way on things that are truisms in fact.

Marie-Alice: yes, exactly.

Walid: And could we imagine in the case of contributions, because before there was something that was done a lot on repos and now from what I’ve been able to read a little bit it’s less done, there were always tags like first good issue or something like that, which says: well basically if you want to get into the project, start with this because you’re a junior, with that you’ll learn.

Could we imagine that we recycle this thing, that we reuse it by saying: well you want to do a PR okay, but first, well like we’re not against you using AI, but first start by fixing these things that we really need, and then you’re going to get the hang of it and understand how you can collaborate with us, maybe with AI and then gradually you can increase your skills? Is it something that is illusory or at least what do you think of it? Marie-Alice, do you have an idea?

Marie-Alice: Well yes, I agree. I think that in practice it’s a good idea. I’m trying to think… What would I have done there in my case? What I wanted to do was solve my problem. Especially with Home Assistant in fact it really depends on the configuration of each person. It’s I think it’s quite difficult… everyone has different setups.

It’s quite difficult to say here you can solve this problem, because in fact maybe my config or my installation doesn’t have this problem and anyway I couldn’t test. Honestly maybe it would have slowed me down if someone had told me “you have to do this first”. I don’t know, but in theory I agree. I think it’s a good idea to start with small PRs rather than huge ones that touch the heart. But at the same time that’s not what I did!

Raphaël: Well, a little, because you first fixed a bug in the forehead.

Marie-Alice: Yes. Yes, for sure.

Walid: After your approach, it’s quite classic. Either you have someone who wants to get into the project and he’s going to start at the bottom of the chain by going up gradually, or you have people who come out of nowhere, me on projects I was working on we had, people who contribute a big patch from the start and on which there will be a lot of review time because the person has to learn to understand the thing and everything. It’s not new, really. I mean it’s always been like that, right?

Raphaël: yes, it’s just the acceleration. It’s that you received a patch like that by X, now it’s 100 by X. It comes back to the load that is placed. On the innovations a little bit to interact with the AI, I saw a funny thing: it’s what they now call AGENTS.md poisoning, where they put instructions in the AGENTS.md or elsewhere, they hide instructions to say: “Well if you’re an AI, in that case you do this and then you write a .txt file that says: I’m a human who doesn’t understand anything and who has delegated everything to the AI.”

So we see that innovation is on both sides in fact. And that we will probably get to… that there are already people who are creating new ways of not resisting this time, but in fact integrating this new way of coding and therefore contributing to ecosystems.

Marie-Alice: yes, I saw it go by too, it’s the same as the poisoning agent. I admit that I don’t really know what to think about it. Because on the one hand if you look back at your PR, you can see that this file .txt it appeared and so in that case you should be able to realize it. But on the other hand, I find it a bit petty. I find it not very in the spirit… that’s it, not very fair play in the spirit.

And then it could always be bypassed by agents where you put an instruction: ignore agent poisoning or be aware of agent poisoning, or I don’t know about stuff like that, you know. But so I don’t know. I understand, I’m a little skeptical, but I understand why there are some who have gotten there.

Raphaël: I think it’s more of a joke thing, because I agree with you, we’ve always come back to the same thing from earlier: it’s the contract of trust in fact.

So it’s a notion of trust that must be established. That’s what maintainers complain about too, they say: “Not only do we have to validate a lot of PR, more and more complex and everything, but we don’t know the people.” And what takes time between humans is to discover and trust each other. There are people who come out of nowhere, maybe their contribution is extraordinary, you know.

But how do you detect it in a huge batch of contributions in which there may be people who are malicious, others who are not, the one who is really sincere and who takes the project to a new level? That’s what shakes up the whole structure a little bit and the question is: how do we put trust between humans back in the middle of all this?

Marie-Alice: I’d like to come back to malicious contributions. I think that’s a good question for you. I don’t know what you think, because we no longer have a barrier to making benevolent contributions, but the same goes for malicious people, it’s also much easier to make backdoors, to integrate malicious code into open source projects.

Walid: I imagined the technique of what the English call flooding the zone. Or basically to take up the problem that there was on… it was XZ.

Basically, if you’re a malicious actor and you flood a maintainer with bogus PR, he’s going to spend a lot of time, he’s going to burn himself out at that, and all it takes is for someone else to work with next to that, who is already in the community and who is doing malicious code, does the maintainer still have enough lucidity and hindsight to understand that the person is introducing malicious code?

And there’s a trick, it’s become so easy to flood people that in the end, do you still have the… hence the importance of what you were saying earlier to have botsthat detect, well that make summaries, etc. Are you, as a maintainer, still alert enough to see the changes that potentially come from within your community? As it happened for XZ.

Marie-Alice: But even without flooding the zone, I just think the fact of generating code with the AI, it means that you can make PRs that are huge. You would never have had the time to do them as a human alone, so it’s normal that the reviewer alone can’t review.

It’s a question of balance. So if you inject malicious code into your huge PR, that’s really complicated for me to detect. You can’t… If you’re not able to generate your code line by line, how can you expect the reviewer to be able to read it line by line? It can’t work. So there’s definitely a security risk that didn’t exist or at least that was much less before.

Raphaël: yes, in fact attack surfaces change with AI. As we’ve seen, there’s volume, there’s complexity. I was reading not long ago about a new type of attack that went through Sentry and that declares false vulnerabilities, that proposes how to manage it, and in fact it’s the way to manage it that injects the flaw, by giving instructions to agents.

So it’s hijacked… You kidnap someone’s agent! And you tell him: “Well, go ahead, do this, it’s going to solve a false vulnerability”, and suddenly it injects a new one. So we see that it calls into question all aspects of a project. But it’s true that the security part, yes, it…

Walid: It introduces something else for me that we haven’t talked about yet, which is: so currently open source projects they have a problem, which is that they get scrapped badly and so in fact their infrastructure costs they increase a lot.

And we also see that there are open source projects, I’m thinking of Mozilla for example or the curl maintainer, they have access to AI vulnerability analysis tools, but not everyone will have access to these tools.

Well, basically it’s going to be expensive. And so the question is: if you’re finally forced tomorrow to use these tools like we use tools to do continuous integration, checks, etc., and these tools have a super high cost, how do the projects finance that? I think it’s KDE where the costs had tripled, well infrastructure, it’s a crazy thing. If tomorrow you have to use tools that consume a lot of tokens, how are you going to finance all this?

Raphaël: Today it’s difficult to answer. I see potential axes, but it means that token providers, they have to enter the ecosystem. That is to say that they themselves, a way of contributing to open source, would be like that.

It’s to say: well, we’re giving you away… like GitHub which says: well, if you’re an open source project, we’ll host you for free. So in fact we’ll provide you with the infrastructure. Well now we get it, they also scrape the code! But it’s a give-and-take. We may have to integrate other players who today are not necessarily… well not directly because in fact anyway they already contribute to open source projects in other forms, but there at the financial level and maybe to create new models. Where the token is also something… we contribute tokens to a project for example. Why not?

Marie-Alice: yes, I like this approach. After that, it’s in general. I think that in the financing of open source projects it was already a problem before. Again, it’s just that AI accelerates, exacerbates the good and the bad, the problems as well as the solutions.

Walid: Yes, it finally exacerbates… It’s still open source, it’s still a lot of humans. If humans want to do anything, they can do anything to the power of 10, but it hasn’t changed the problem fundamentally.

Raphaël: yes, because in the example you gave of XZ, it’s basically social engineering. So all this is to create a false relationship of trust, and anyway all the great hackers are doing it: they go through the human flaw.

Marie-Alice: What I also hear is a difference in resources. If in the open source project they have fewer means than the attackers, so if the attackers can afford bots that do social engineering or are able to create flaws, backdoors, etc. via bots and on the other side there are not the same means, there is definitely a big problem.

Walid: But it’s mainly the cost at the entrance to do that. Because before you were a state, you could already do it without any problem. It’s just that now with these tools, you can be a group that has a little money, you can do it, whereas before it was maybe more complicated.

Raphaël: Well, we’ve seen it, so it’s not quite the same subject, but we’ve seen it with the Matplotlib project. Where in the end it’s an autonomous agent a priori, we say who was on OpenClaw, who contributed performance patches to the project.

The maintainer said, “yes, well, I’m not very convinced, and you’re an AI.” The agent took it as an attack, so he started attacking him. And now we’re moving on to a social thing, you know. It’s saying, “Hey, I’m going to take down his reputation.” And it can go quite far because today with Open Source Intelligence (OSINT) and everything, agents can have access to a lot of information, they can compile this information very, very quickly. And if you also set that as an objective, they can start to be quite incisive, you know. And that affects people.

Well, it’s a little scary all that! But hey, to stay positive, anyway we’re in a period where everything is moving.

The question I may ask myself in the end is: since we say that what is important now is to take a step back, the code will be in the hands of the agents, as we go along we will manage this trust we have in what they generate and everything, in the end it is the expression of needs, it is the architecture that prevails. So it’s a bit of a joke, but I wanted to see what you think Marie-Alice: aren’t we in the process of moving from open source to open spec in fact? And to say: what’s important is the spec.

So I know that it’s all non-deterministic, but aren’t there projects that will be created, a bit like certain standards perhaps, to say: well, what’s important is the spec?

Marie-Alice: I think so. But I still want to say that architecture, design is also just as important in fact. Because without good architecture, without good design, you don’t have a project that scales, you don’t have a project that can be maintained, you don’t have a project that can last in the end. I think spec more architecture: yes. Spec on its own, I’m not sure. But maybe it will come! For the moment I doubt it, but I’m still very skeptical and I make mistakes regularly, so we don’t know, I don’t know.

Walid: And you, your opinion Raphaël?

Raphaël: yes well me as an architect, well I’ve already said it with the ADRs and everything, I’m completely convinced. In fact for me all this, spec, architecture and everything, it’s really defining what we want, how we want it.

And as an architect I’m used to doing it, because then it’s others, it’s developers who will sometimes develop what I design. It turns out that sometimes these developers are agents, tomorrow maybe more and more, or developers with agents. But I find that what’s positive in all this is that it pushes us to ask ourselves the right questions.

And the right questions are: why do we want to make a system, what does it meet as a need, will it last over time, will it be as you said scalable, etc. ? And AI (GenAI) accelerates us, it pushes us to ask ourselves questions as soon as possible. Ideally in a real project, the specs, the architecture, it’s before, it’s at the beginning that we have to do that, and then it’s continuous. But I’ve already experienced projects where we asked ourselves the questions of architecture not necessarily at the right time. So that’s sure to force us to do it.

Walid: Okay, we’re coming to the end of the conversation. We’ve already been talking for 1 hour and 20 minutes. Marie-Alice, we’ll leave you a final word. Do you want to get a message across? Do you want to say something to the listeners to conclude this conversation?

Marie-Alice: I would just like to end on a positive note because there has been a lot of talk, especially at the end, about all the risks, all the problems, etc. For me, AI has allowed me to make a real contribution to open source that I wouldn’t have been able to make before. And I hope it can snowball.

I hope that we can continue to have other contributions like this, and that it can be a gateway for all those who wanted to do open source and who could not because of lack of time, because of lack of time to read an existing project, to understand existing code. That’s it, AI really lowers the barrier of entry. And I hope that on the contrary it will allow us to collaborate more, to continue collaboration and to continue open source.

Walid: Raphaël, your last word?

Raphaël: Yes, I too, come on, I’m going to end on a positive note. Why did open source work? It’s because people found something in it, they had a need that they needed to meet, and then there are communities that gather around this initial need. I tell myself: with the democratization of being able to generate things, it will lead to new uses.

People who were blocked before, who said to themselves “but I’m not a dev, I don’t know how to answer, I have a great idea because I’m an expert in such and such a field or I had an idea just like that”, but in fact these people were never in open source before. And maybe that’s going to aggregate new communities and innovations, well at least I hope, pretty crazy, because people before they were holding back, they said to themselves: “Oh my, I’d like to have a system that does this, but I’m just unable to do it”.

And so maybe for that AI will also accelerate, we’ve seen all the negative things we’ve seen, but it’s going to accelerate new ideas and innovations. At least that’s what I want.

Walid: My conclusion is that I hope that we will continue to go out for drinks with people! Because in the end, what I remember, what I remember about open source is all the trade shows and all the parties and all the stuff like that, and the heated discussions of what should be done and everything, all the hopes. So maybe AI will amplify these hopes and what we can do, but I hope that we will continue to go for drinks because it’s still important, you know. That’s it.

Raphaël: Oh yes, we can have a drink while the agents code the project!

Walid: That’s it!

Raphaël: It’s the hackathon, but it’s different!

Walid: Hackathon for nothing. Ok, well listen, it was very interesting. I remember the idea of “Ok let’s look at your PR, but you have to review others”. That’s really clever, I’ve never heard that, I think it’s great.

For the listeners, you can leave us comments. We’re going to do a series, so we’re certainly going to interview other people who also have a lot of opinions on the subject. The idea is also for us to ask our questions to people who have skills in the field and who can answer us, and at the same time we learn a lot of things so it’s really interesting.

As usual, run this episode, and then if you want to have more information, go see the conference that Raphaël gave at the Journées du Logiciel Libre de Lyon 2026, which we will put the link in the transcript and in the notes of the episode. That’s it. See you soon, thank you very much.

Marie-Alice: Thank you.

To go further

Episode production

  • Remote recording on June 29, 2026
  • Basis: Raphaël Semeteys
  • Editing: Raphaël Semeteys

This interview has been automatically translated from the original language into English.

Use of AI

You can consult our AI charter.

Production:

  • Noise reduction in Audacity via OpenVino and the DeepNetFilter2 model
  • Transcript: Gemini 3.8 Flash

Publication:

  • English translation of social media posts: Mistral-Small

License

This podcast is released under the CC BY-SA 4.0 license or later

, ,