Navigating the Growth of Open Source in AI with Mitch Ashley | Open Source Summit NA 2025
Transcript
Hey everybody. We're back at the Open Source summit in Denver. We're talking with Mitch Ashley, who's vice president and practice lead for Software Lifecycle Engineering at the FU Room group.
And we're gonna have a little chat about, well, what's going on in the open source community, because I gotta tell you, there's more projects than I can shake a stick at. I cannot keep track of all of them. And sometimes I feel like they're a little overlapping.
So you're the analyst who keeps track of this stuff for if you tour 'em. How do you kind of sort this out a little bit so that it makes some sense? Well, you know, when I lived in New York, we used to go to the festivals on the weekend and there is a plethora of every kind of food you can have, depending on which neighborhood you go to.
It's kind of that way in open source. There's neighborhoods of different kinds of projects and who you talk to, whether it's Steven Chen from over in, in Neo four J, you know, used to be with uh, JFR or Tracy Reagan. It's kind of, you know, know some, know some people who know some people and keep track of it that way.
That's, that's at least to find out what new things are going on. I mean, you can read the announcements, you can try to follow the, the Discord servers or the, you know, the email distribution lists. What I do is I try to assemble that into what's important to follow, what's really kind of, not every announcement is worthy of Oh, I need to take 30 minutes to read and investigate this.
So I just produce the, uh, agent AI top 10 agent AI open standards to follow, meaning things that are happening in open source like the A two A announcement yesterday about the Linux Linux Foundation. Taking that over, starting the project for that on GitHub. So that's certainly one way.
Um, I read tech strong sites and things like that. Of course, you know, little self-promotion here, shameless. Mm-hmm.
Uh, as well. So, you know, I think that's, that's one way you have to have an area of interest too. 'cause there's just so many things.
Like I tend to follow Open telemetry and anything to do with agents and things like that. So right now, what are, say the top three open source projects that got your attention, that feels like they're doing the most to move the proverbial needle? Well, you know, open, open telemetry is still kind of the, in a good way, the behemoth, it's the model of talk about vendors cooperating and, you know, building a really great ecosystem of open source and then differentiating in their own technologies.
So I sayre restas of that 'cause there's developments happening around AI observability and things like that we know we need, but then there's, you know, new developments, even open source project, but it's not part of a foundation or organization is like NCP servers that anthropic is still supporting. Now you might ask why does anthropic not need to donate it to a consortium? Or maybe they will at some point.
And why did Google do that? I think it's probably because Google's in a position to, uh, wield a little bit more power. And so putting their software a two A in a consortium really does help with sort of the neutrality and blend it up well.
We have a good tracker record with things like Kubernetes and Istio to somewhat and things like that. So one of the ongoing conversations in any sort of open source event is this tension between wanting to contribute to the community and somebody needs to make some money here and justify the return on the initial investment. And mm-hmm.
I feel like that subject has not quite dissipated. It's still floating around here. Sometimes projects get forked and then, you know, the community ships and moves over, but there's somebody running an enterprise IT organization somewhere who's like trying to wrap their head around, how do I manage this chaos sometimes.
So are there tips for enterprise folks as they kind of look at open source and say, how should they be thinking about whether to dive into a project to use something or not? I mean, should it be like, number of contributors to the project is, is there more than one vendor? What are, what are some of the things you look for?
Well, there's different flavors of it. I, but I think the rule of the road is, it's kinda like in college it's a great party until somebody breaks something and then your parents come home. Right?
Soon as somebody messes things up for everybody, that's when it gets a lot of attention about, is this the open source we should be using? So changing a license, be making it more restrictive, maybe having too much control over open source. I mean, generally there are companies who build, have their business model around an open source of some part of their product.
Maybe a lot of it like a GitLab and others that are kind of much more, well we're really here to make money and kind of just do open source to do open source. So you can pretty much ferret those out pretty quickly of who's contributing. So mostly the company and yeah, there's open source, but you're probably gonna be using the commercial version.
And then there's ones that have a lot of people contributing to it and are very healthy and have a lot of, lot, lot happening with it. So I would look at really companies that are heavily involved. More importantly, who's the governance of the project, who's making those decisions around, okay, these are all things submitted, we're gonna work on next and we'll take these contributions from these people.
As opposed to, well, we're this company and we don't like Microsoft. We're this company and we won't work with Google's code. That's not gonna help anybody.
Oh, One of the things of course that's top of mind here is ai, and I can't help but feel like we're, it feels like the early days of proprietary OSS and databases, right? For a long time they were the dominant players and they were the proprietary vendors, and then the open source community caught up and arguably surpassed them. Is that about to happen here with ai?
I mean, we've seen some open source AI projects here, but there's not that many yet. So is that like the next wave? I definitely think so, and for one reason, developers and developers, they're gonna create things.
They're gonna find problems to solve. And now you can argue whether that's gonna come out of a vendor like MCP from philanthropic or you know, HOA with Google. But people are gonna create projects.
They're gonna see needs that they're gonna build open source and start a project and do that. It, it's just that they're now doing a lot more development around ai or at least starting to. So in the, in the AI community, I don't know that it was as big of a factor of to develop open source software probably.
'cause there's a lot of proprietary investment and intellectual property that you're controlling, uh, in, in that environment. So I think as it gets to the broader population of software developers and communities, absolutely we'll see a lot more ai open source projects. All right, so you get that little crystal ball, you pull it out every now and again.
Oh, the eight ball, that's a eight ball, that one. And you rub it. As you look into the second half of this year, what do you think you're gonna see?
Well, the, the first part of this year, of course, was sort of in, in the AI space, was dominated by MCP and A two A. You know, there's some other things coming up behind it like agent DNS and agent communication protocols and some things like that that are in the wings. I think we'll see those development.
I think we're gonna see more projects that we don't know about yet that are just kind of get sprung on us and two months later, a hundred companies are saying that they're adopting. It doesn't mean that the project or the spec or the software's mature yet, but I think, I think we're gonna see more of that kind of innovation, very, very short, uh, cycles, innovation cycles happening just like we see with new versions of models and new companies and releases and tools. So I, I wouldn't make any bet on one technology at this point.
I'd look at what people are making big bets on, uh, in terms of open source, but also keep in mind that what may be cool today may get SLAs past or supplanted in nine, 12 months from now. Something in the next generation may come along. Right.
Yeah. And the other thing I look at too is the stack. Mm-hmm.
It keeps getting bigger. Mm-hmm. At some point, will this stack start to compress a little bit?
You know, there's a lot of overlapping capabilities and you know, it takes a small village, maybe even an army these days to actually go build something that always struck me as not necessarily sustainable. So can we like find another layer of abstraction to simplify all this? Maybe, Well, there, there's a lot of, there's some talk about should we focus on bloat?
Should we take focus on taking out all the extraneous stuff? Would that solve a lot of our vulnerability problems that 'cause the cup code? We don't need code we don't use.
That's always a tough proposition to pay somebody to go do that or somebody to go through the toil in software world of doing that kind of work. I, I tend to think not, I think people are more practical about, well just keep adding to it. Maybe AI helps us bring down some of the technical debt on our software.
I'm not gonna say that's the panacea to the answer, but I don't, I don't see the pattern changing. Not significantly. You mentioned technical debt and of course you can't come to this conference without somebody, you know, basically having a, a moment of silence that to mourn the fact that we have so many vulnerabilities in open source code and we don't always find ways to easily fix that.
And it's, it's a problem, but it, it gets a little bit better. But, and do you think at some point we might solve this problem or is this gonna be like, you know, death and taxes and it's always with us. It's always gonna be there.
But I think if, if the, if the models that we used to generate code really get trained and emphasize secure code, either fixing or generating secure code instead of, we've heard about different models creating lots of vulnerabilities in the code generated, otherwise we're relied on scanning and tools and people to catch things earlier in the cycle. All those things help. But still, if you're gonna create more software faster, you better create more secure software faster.
And I think that's, that's the answer. To get the most benefit, make the biggest dent in, in security and vulnerabilities. All right.
You go to a lot of these conferences, as do I, and I'm often amazed at how many actual open source consortiums there are. So between them all, do we need like, um, an orchestrator for all the different consortiums so that somehow or other they can kind of work together? 'cause I feel like there's still a significant amount of duplication of effort running around.
Well, I think it's all determined by the sponsors who will fund those projects and who will fund those organizations and how that works. You can usually kind of, you know, follow the money they say. Right?
I think that's, that's what makes it tick. And I know it's not a commercial venture, but still you have to have financial support to do all these things. So until there's a reason for either not creating another one or a downsizing one or combining them, you know, we'll operate on the path we are.
And I think we'll see more things pop up rather than less. All right folks, you heard it here. Hey, even in the open source community, money still talks.
We'll be back in a minute.