ryrona I have barely seen any AI code committed to serious open source project as of yet, and absolutely none to security and privacy focused project.
horde KeepassXC
Interesting. More specifically, they used GitHub Copilot for 11 easy bug fix and test case commits between August and November 2025.
Here is a link where they write more about it, and the controversy and loss of trust in them their decision caused:
https://keepassxc.org/blog/2025-11-09-about-keepassxcs-code-quality-control/
They also disclose all AI commits there. Looking at them and the reviews, I doubt using AI improved their productivity here. But at least they tested the water to see how the community would react, and they don't seem to have made any further use of Copilot after that.
monozygote AI is here to stay. I resisted it for a long time mainly b'coz colleagues had become complacent. AI can churn out huge amount of code in no time, so folks became lazy, didn't review it beyond cursory glance, merged and deployed it.
The pace was suddenly enormous and there was a huge support from the management (they don't care about technical stuff, only $$$) because they saw it as "crushing the competitors" game. Then the breakages started, production failures etc.
There is a huge reason I think it is more interesting to see how and when serious open source projects adopts AI coding assistants than how and when closed source for-profit companies do it. For-profit companies have many reasons to invest in using AI that has nothing with productivity and usefulness today to do, including the fact that AI might boost productivity and be useful in a not too distant future, and having the company being totally unprepared and inexperienced in using AI at such a hypothetical future will make the company fall too far behind competition and become irrelevant, and that is something they must guard against by starting to use AI already now before it is boosting productivity or is being useful. Another advantage of looking specifically at serious open source projects, especially in the security and privacy sphere, is that it is the developers themselves that make the decision whether to use AI or not, and whether it is useful or not. In a for-profit company, it is management that is making that decision, and they rarely have prior experience in software development, nor even understand it, and thus makes poor decisions.