Developer Tools

New AGM framework helps OSS maintainers govern AI agent contributions

AI coding agents flood open-source projects – new AGM framework restores maintainer control

Deep Dive

A new paper from researchers at multiple institutions tackles a growing crisis in open-source software: AI coding agents generating contributions faster than maintainers can assess risk, evidence, and accountability. The authors propose the Agent Governance Manifest (AGM), a repository-hosted boundary resource that acts as a bidirectional governance contract between contributor-side evidence preparation and maintainer-side verification. A diagnostic audit of 50 GitHub repositories found widespread governance artifacts but no project-wide arrangement coordinating shared rules, preparation obligations, verification rights, and maintainer decision authority across AI-mediated workflows.

The AGM was evaluated in two controlled studies. In a reviewer-side evaluation with 15 participants and 75 task-level outputs, AGM-supported materials improved exact risk-label recovery from 15/37 (40.5%) to 37/38 (97.4%), and perceived review support jumped from 3.27 to 6.14 on a 1-7 scale. A contributor-side feasibility check with 15 participants completing 45 tasks showed all final packages represented the core governance state correctly, with 41 passing strict structural validation. The study develops a three-layer framework of agent-readability, traceability, and governability, theorizing agent-mediated contributions as governable boundary objects. This work advances compliance-enabling digital innovation governance while preserving maintainer decision authority.

Key Points
  • AGM improved risk-label recovery accuracy from 15/37 (40.5%) to 37/38 (97.4%) in reviewer evaluation.
  • Perceived review support increased from 3.27 to 6.14 on a 1–7 scale with AGM materials.
  • Framework includes three layers: agent-readability, traceability, and governability for AI contributions.

Why It Matters

Without governance frameworks like AGM, open-source projects risk being overwhelmed by unverified AI contributions.

📬 Get the top 10 AI stories daily