Error Icon

Something went wrong. Please try again

Evaluating Open Source Trends: From 2020 to 2026 Hero Banner

Evaluating Open Source Trends: From 2020 to 2026

Last Updated: September 9, 2026 | 4 min read

by Yuriy Markov

open source trends

This article is intended for CIOs, CTOs, engineering leaders, and enterprise architects evaluating open source software, open source AI, and software supply chain risk as part of their technology strategy.

In 2020, the question was whether open source software would keep growing through disruption. It did. Six years later, the question has changed entirely. Open source is no longer a licensing preference or a cost efficiency play. It is the substrate the entire artificial intelligence industry runs on. Open source AI models now route a majority of production AI traffic. The software supply chain has become a battleground. Open source maintainers are outnumbered by the attackers targeting them.

The question CIOs asked in 2020 was whether to adopt open source software. That question is closed. The question now is whether enterprises can manage what they already depend on.

OSCI in 2026: Still the Benchmark, Now Broader

EPAM's Open Source Contributor Index (OSCI) has tracked enterprise contribution to the open source community since 2019. It remains the industry's most consistent lens on which companies actually build open source software, not just talk about it. The index now covers roughly 262 commercial organizations across 10 industries. It measures two things: Active Contributors — employees with 10 or more commits a year — and total Community size, everyone with at least one commit. Since launch, it has processed data on tens of millions of contributors, billions of commits, and hundreds of open source licenses and programming languages.

EPAM's own trajectory tells the story. Outside the top 25 at launch in 2019. A consistent top-20 presence in the open source community from 2023 through 2026. Ninety-plus open source projects, up from 70. Vividus, EPAM's test automation framework, is among the leading open source solutions driving that climb. In 2026, EPAM took the next step and commercialized OSPulse — turning the index's methodology into a product organizations can use to see not just where they rank, but where their open source contribution is heading.

The companies at the top haven't changed much. Microsoft, Google, Red Hat, Intel, and IBM still lead. What's changed is what sits below them: AI labs and infrastructure companies have entered the rankings in force. Open source in 2026 is as much about models and datasets as it is about code repositories.

One pattern from the original analysis still holds, and it matters more now than it did in 2020: smaller, open-source-native companies — Mozilla, GitHub, Canonical — have historically posted dramatically higher active-contributor rates as a share of headcount than the giants above them. Size does not predict impact. Focus does. Businesses that build open source into how they work outcontribute organizations ten times their size that treat other projects as a side activity.

Source: EPAM OSCI – GitHub

The Real Story Since 2020: Open Source AI Goes Mainstream

Here is the shift the original analysis could not have anticipated. Open-source AI stopped being a side project ages ago. Now it's the main hub for everything happening in AI.

The numbers make the case on their own:

That last figure comes with a warning enterprise leaders cannot ignore. Usage does not equal economic value. Open source models account for roughly a third of real-world AI activity and capture only about 4% of the revenue. This is the funding and sustainability problem the open source community has fought for a decade, now playing out at AI-industry scale — critical infrastructure, maintained by a small number of people, generating enormous value for companies that contribute nothing back.

Qwen and DeepSeek command a commanding share of global model downloads — Qwen alone surpassed Llama in September 2025 to become the most-downloaded LLM family on Hugging Face, and Chinese-developed models now lead in derivative uploads as well. (Stanford University, Human-Centered Artificial Intelligence)

Cumulative downloads of major open-weight LLMs on Hugging Face (November 2023 – October 2025)

Monthly uploads of new fine-tuned or derivative models to Hugging Face, by base-model developer (September 2024 – September 2025)

Western labs and governments have responded in kind — OpenAI's GPT-OSS, AI2's OLMo, Google's Gemma — and national governments in South Korea, Switzerland, and the EU have launched sovereign AI initiatives that treat open source access as a matter of digital independence, not cost. (Hugging Face)

One distinction matters for anyone evaluating this space, and not everyone gets it right. Open weights means downloadable, runnable, modifiable parameters, often without training code or full data documentation. Open source AI, under the Open Source Initiative's definition, requires both. Most of what is driving 2026's adoption numbers is open weights, closer to free software in spirit than to a fully documented open source license. That is a looser standard than the one enterprises expect when they evaluate open source components, and treating the two as interchangeable is a governance risk waiting to happen. (Stanford University, Human-Centered Artificial Intelligence)

This divide has a sharper edge in 2026 than a licensing definition suggests. The perception that anyone with LLM access can now ship production-grade software has fueled a wave of thinly-built AI-wrapped SaaS products across mobile and enterprise categories alike. The numbers don't support the confidence: an MIT NANDA initiative report found that only about 5% of enterprise generative AI pilots achieve measurable P&L impact, with the vast majority stalling out with little to no return. Freelance and indie developers show a similar pattern — high volume of AI-assisted projects launched, low volume that survive contact with real users. The practical fork for enterprises isn't "open source vs. proprietary" as an ideology anymore; it's open source holding the infrastructure layer while proprietary models compete for the application and SaaS layer, with the actual decision increasingly driven by total cost of ownership, auditability, sustainability, and digital sovereignty rather than either side's marketing.

Enterprise Adoption: From Cheaper to Mission-Critical

RedHat's original projection — 8% growth in enterprise open source adoption — was conservative. Red Hat's most recent State of Enterprise Open Source research shows the vast majority of IT leaders now consider open source software core to their infrastructure strategy. Proprietary software's share of the stack keeps eroding — across financial services, telecommunications, and government alike, as more companies realize that flexibility and speed matter as much as licensing cost. The reasons have shifted too. Flexibility, faster access to current technology, and easier hybrid cloud adoption now rank alongside — in some surveys, ahead of — the cost argument that drove adoption a decade ago.

OpenLogic's 2026 State of Open Source Report, produced with the Open Source Initiative and the Eclipse Foundation, points to what comes next. Enterprise Java modernization. Software bill of materials (SBOM) generation. License compliance. These are no longer edge concerns — they are standing demand for any organization running open source software at scale, alongside the AI/ML adoption curve Red Hat first flagged back in 2020. Many startups are built entirely on open source ecosystems from day one, a different starting point than the enterprises that migrated off proprietary systems in open source's early days.

Open Source Funding: The Sustainability Gap Enterprises Depend On

Enterprises consume open source software at a scale that has outpaced how they fund it. The imbalance is no longer anecdotal — it shows up clearly in the data.

60% of open source maintainers are unpaid as of 2024, according to Tidelift's 2024 State of the Open Source Maintainer Report — a figure that has barely moved since 46% of maintainers reported receiving no pay in 2021. The direction of travel matters here: as enterprise reliance on open source software has grown, the share of maintainers doing that work for free has grown right alongside it, not shrunk. Nearly 60% of maintainers say they've quit or considered quitting a project they maintain, and the maintainers most likely to implement critical security practices are the ones who happen to be paid.

The scale of what's at stake makes the funding gap harder to justify. The total value of open source code has been estimated at $8.8 trillion by Harvard Business School researchers — the cost enterprises would face rebuilding that software internally if it disappeared tomorrow. That figure dwarfs the resources flowing back into the projects that create it.

A handful of structural responses are emerging, though none yet close the gap at scale:

There's also a resource asymmetry shaping how this plays out. Enterprises briefly gave employees near-unlimited AI access in 2026, and it got expensive fast — Uber burned through its annual Claude Code and Codex budget in four months, and reports surfaced of one company spending $500 million in a single month before usage limits went in. Even with the budgeting correction that followed, the baseline available to a well-funded engineering org still dwarfs what most independent maintainers can spend on AI tooling — tilting some of the corporate-vs-community balance further toward the companies that already contribute the least back. It's not a settled outcome, though: well-resourced individual maintainers have repeatedly shown they can out-execute larger, slower organizations on specific problems by staying flexible. Which side compounds that advantage over time is still an open question.

The pattern is clear even if the solution isn't finished: enterprises that treat open source funding as optional are underwriting their own supply chain risk. The organizations getting ahead of the security problem described earlier in this piece are, not coincidentally, often the same ones funding the maintainers behind the code.

Security: The New Center of Gravity

In 2020, "security of the code" was a perception problem — IT leaders worried about known vulnerabilities that, on balance, weren't the real risk. That framing no longer holds. Security is the risk, and the blast radius of a single compromised package now reaches thousands of downstream systems within hours.

The software supply chain has industrialized as an attack surface. Researchers tracked more than 450,000 new malicious open-source packages in 2025 alone — a 75% jump year over year. The cumulative total of known and blocked malware has passed 1.2 million packages across npm, PyPI, Maven Central, NuGet, and now Hugging Face. npm took the brunt of it — more than 99% of all open source malware now lives there. Self-replicating worms — Shai-Hulud, then Shai-Hulud 2.0 — compromised more than 1,000 widely used open-source libraries by harvesting maintainer credentials and propagating automatically, exposing an estimated 25,000 downstream repositories. High-profile packages with billions of weekly downloads were hit directly. State-linked actors, including groups like Lazarus, are now behind a meaningful share of the droppers, info-stealers, and persistent backdoors embedded inside the tools developers trust every day. (Source: Swif, Supply Chain Attack Statistics for 2026)

Two structural failures sit underneath these numbers, and both are organizational, not technical:

  • Open source maintainer sustainability is broken. A small number of people — often volunteers, often without institutional support or expertise on staff — maintain the infrastructure that generates enormous economic value for enterprises that contribute nothing back. Detection-to-removal times for known vulnerabilities still stretch into days. That's more than enough time for a self-replicating attack to spread through every downstream dependency.

  • AI is accelerating both sides of the fight. Attackers use AI to discover vulnerabilities and generate convincing malicious packages faster — including "slop-squatting," which exploits AI agents and coding assistants that hallucinate package names (Source: Swif). Maintainers, meanwhile, are flooded with automatically generated bug fixes and vulnerability reports they don't have the capacity to triage — curl maintainer Daniel Stenberg shut down the project's six-year bug bounty program in January 2026 after the share of genuine vulnerability reports fell to around 5%. (Source: LeadDev)

The strain isn't only technical. A Scientific American analysis of DORA and Multitudes research found that developers using AI assistance are shipping more pull requests but also logging more out-of-hours commits and more post-release rollbacks — a productivity gain that arrives bundled with burnout risk. For open source maintainers specifically, that translates into a flood of AI-generated pull requests of uneven quality, review burden from contributors without domain expertise, and a recurring, avoidable failure mode: secrets and API keys accidentally committed by poorly-instructed AI agents into public repositories.

Notably, even the most AI-skeptical corners of open source have started adapting rather than resisting. Linus Torvalds spent years dismissing AI-generated code as overhyped, but by mid-2026 had reversed course, calling AI "clearly a useful" tool and telling kernel contributors who object that they're free to fork the project. The Linux kernel now has a formal policy permitting AI-assisted contributions, provided a human reviews, takes responsibility for, and discloses them — a middle path between banning AI outright and letting it run unsupervised, which may be a more realistic model for other projects than either extreme.

The four challenges from the original analysis — code security, support, compatibility, internal skills — are all still live. But code security has moved. It is no longer a perception gap enterprises need to get past. It is a quantifiable operational risk. SBOMs, dependency scanning, and license and provenance verification are not hardening measures anymore. They are baseline requirements for any organization that wants to explore open source adoption responsibly.

EPAM's Open Source Involvement

EPAM's commitment to open source innovation has deepened alongside these shifts. Ninety-plus open source projects, up from 70. Continued development of the OSCI platform, now live at opensourceindex.io and on GitHub. And OSPulse — the commercial extension that gives organizations a way to act on their open source community data, not just observe it, backed by EPAM's own expertise in managing open source at enterprise scale.

The Takeaway

The original thesis holds: open source adoption is structural, and it is not slowing down. What has changed is the story. Open source is no longer just about infrastructure software displacing proprietary software. It is inseparable from how AI systems get built, distributed, and governed, and it carries a funding and sustainability burden enterprises can no longer treat as someone else's problem.

Organizations that get the most economic value from open source in 2026 treat contribution, security, and AI model provenance as one strategy, not three separate conversations. The businesses that lead will be the ones that manage what they consume as rigorously as they consume it.

1b72e41f98edf49e22333b1e4f73ffa9

Yuriy Markov

Lead Software Engineer

Loading...

Get updates in your inbox

Subscribe to our emails to receive newsletters, product updates, and offers.

By clicking Subscribe you consent to EPAM Systems, Inc. processing your personal information as set out in the EPAM SolutionsHub Privacy Policy

Loading...