Open Source, AI and the Bear — Where We’re Winning (and Where We’re Not)

This year, the Linux Foundation’s North American open-source summit was held in Minneapolis, Minnesota. The three-day event kicked off with a keynote from the Foundation’s executive director Jim Zemlin entitled, “Sometimes You Eat the Bear and Sometimes the Bear Eats You.”* In Jim’s 40-minute talk he went through where open source in AI is dominating, where it’s losing, and what we can do to address it.

The following highlight reel was created from a recording I made from the audience. 

*Jim chose the title as a nod to Ethan and Joel Coen who, like Jim, hail from the great state of Minnesota.

The Bear We Ate: Open Source Owns the AI Stack

Jim’s core argument is that open source is not just part of the AI software stack, it is the AI software stack. It starts with Linux and Kubernetes at the base and runs up through PyTorch for training, inference tooling like vLLM, open weight models, and agent protocols like MCP.

[SLIDE: Open source runs at every layer above the hardware stack]

Where the Bear Bit Back: The Data Laye

The one layer of the stack where open source is losing ground, however, is data. Training data is getting less open, not more, which makes the context that lives inside your own organization the real differentiator. As Jim put it, intelligence doesn’t do much without context. Context, he noted, is the C in MCP. (Something that should have been obvious to me, but when Jim said it a lightbulb went on.)

Jim expects open-data consortiums to emerge as a counter-reaction, limited more by money and will than by technology.

[SLIDE: The AI stack status check — Data is the moat]

AI and Jobs

One topic near and dear to the hearts of the audience was how AI would affect developer jobs. Jim’s answer was that not only will everyone still have jobs, but the demand for technical jobs is increasing. The reason is that although AI coding tools have gotten good and productivity is way up, context still matters, and context lives in people, not the model.

[SLIDE: AI isn't going to kill tech jobs — 31% projected hiring increase]

The Bear Now Eating Us: Cybersecurity

When it comes to cybersecurity, AI has flipped the balance, and open source has a fair amount of catching up to do. AI can now find and exploit vulnerabilities faster than patches can ship. Jim cited Google Mandiant’s M-Trends 2026 report, which tracks mean time to exploit falling from 63 days in 2018 to -7 today.  In other words, exploits now land, on average, before a patch even exists. 

The tools needed to defend exist. What’s needed is collective will to remediate, fund maintainers, and coordinate disclosure.

[SLIDE: Mean time to exploit, 2026 — negative seven days]

Now What

Jim concluded his keynote with five asks for anyone who builds or consumes open source:

  1. Adopt the defender stack, now
  2. Wire AI into your secure SDLC
  3. Fund the maintainers carrying the load
  4. Join AAIF, x402, OpenSSF, your CNCF SIG
  5. Coordinate. Disclose. Share defensively.

Phase one saw open source eat the bear in AI. Phase two, the bear is eating back. But with collective will, Jim argues, this bear can be eaten too.

Pau for now…


Comments

Leave a Reply

Discover more from 808labs

Subscribe now to keep reading and get access to the full archive.

Continue reading