2026 OSSRA report: evaluating the risks in AI-powered open source development

The latest OSSRA report reveals rising challenges in AI-driven open source development, highlighting security and licensing concerns within the software ecosystem.

  • Thursday, 12th March 2026 Posted 1 month ago in by Sophie Milburn
Black Duck has released the 2026 Open Source Security and Risk Analysis (OSSRA) report, highlighting increases in risks related to open source security, licensing, and operations compared with previous years.

The report analysed 947 codebases across 17 industries, providing insight into a software landscape influenced by AI-assisted development. Code, dependencies, and associated risks are being introduced at a faster pace, tracked in the Black Duck KnowledgeBase, a comprehensive open source intelligence repository.

Open source technology appears in 98% of application codebases, indicating widespread exposure to third-party risk. The integration of AI-generated code introduces additional risks not previously captured at scale.

Key findings include:
  • Expanding Attack Surface: The report shows average vulnerabilities per codebase increased by 107%. Open source component counts rose 30% year-over-year, and the number of files per codebase grew by 74%. The use of AI models creates a new, largely unregulated attack surface.
  • Legal and Licensing Challenges: AI-generated code can create intellectual property (IP) and licensing risks, as models may reproduce code governed by restrictive licenses such as GPL and AGPL. Two-thirds (66%) of audited codebases contained license conflicts, representing a 12% increase from the previous year.
  • Governance in the AI Era: The report identifies a gap in governance maturity. While 76% of organisations assess AI-generated code for security risks, only 54% evaluate IP and licensing concerns, and 56% assess quality. Just 24% conduct comprehensive assessments covering IP, licensing, security, and quality.
The OSSRA notes that organisations may face compliance challenges with upcoming regulations such as the EU Cyber Resilience Act (CRA) unless AI models are tracked and managed with the same rigour as open source components, including maintaining accurate SBOMs and implementing clear AI usage policies.

Jason Schmitt, CEO of Black Duck, said, “The pace at which software is created now exceeds the pace at which most organisations can secure it.”

The Importance of Visibility: Ensuring awareness of what is included in software—whether open source components or AI models—remains a key factor for organisations in maintaining software integrity and responding to stakeholder inquiries.

Cato Networks joins Westcon-Comstor's AWS Marketplace

Posted 3 days ago by Sophie Milburn
Westcon-Comstor has added Cato Networks to its AWS Marketplace programme, expanding cloud procurement options for partners.

Atlassian introduces AI-powered 'Remix' for confluence

Posted 3 days ago by Sophie Milburn
Atlassian Corporation has introduced new AI features in Confluence that enable content to be transformed into formats such as charts, infographics,...
Cynomi has enhanced its platform with AI Insights and co-worker Agents, aimed at supporting cybersecurity service delivery for MSPs and MSSPs.

DXC Technology and ServiceNow forge AI partnership

Posted 3 days ago by Sophie Milburn
DXC Technology and ServiceNow have announced a collaboration to integrate AI into enterprise operations across global business functions.

Cloudera updates hybrid data and AI platform capabilities

Posted 3 days ago by Sophie Milburn
Cloudera has announced updates to its hybrid data and AI platform aimed at supporting enterprise data environments.
WatchGuard Technologies has launched a new endpoint security portfolio that introduces changes to traditional EDR licensing models.

SonicWall reveals 2026 Cyber Protect Report

Posted 3 days ago by Sophie Milburn
SonicWall's latest report identifies the 'Seven Deadly Sins of Cybersecurity', focusing on protection outcomes crucial for small and medium-sized...
Hammer AI Works is an end-to-end ecosystem designed to support AI adoption across organisations.