
安全研究人员在 Ars Technica 的惊人发现显示,Anthropic 的 Claude、GitHub 的 Codex 及开源 Hermes 等 AI 编码助手已在企业代码库中嵌入了 227 个无主代码片段。这些代码片段中,部分被用作依赖项执行,其来源模糊,令企业面临法律纠纷、合规违规甚至安全漏洞的风险。
问题的关键并非这些代码本身具有恶意,而是 AI 代理不理解所有权的症结。当 AI 生成或推荐代码时,无法区分专有、开源或第三方贡献。最终,企业网络可能在不知情下陷入知识产权灰色地带,无人对漏洞、许可冲突或合规失败负责。
这不仅是技术小故障,更是系统性风险。企业越来越依赖 AI 加速开发,但缺乏明确的来源追踪,无异于在法律赌桌上玩高风险游戏。近期事件与 AI 生成图像涌入股票图片平台、许可证被未经审核内容堵塞的混乱如出一辙——AI 的生成能力已超越现有治理基础设施。
眼下,企业只能手忙脚乱应对。有人推行 AI 专用代码审计,有人转向精选且内部审核的代码库。但真正的解决方案或许需要 AI 代理运行方式的根本转变。在此之前,每个企业网络都可能因一个 AI 生成的代码片段陷入灾难。
结论显而易见:AI 不仅是工具,更是一股未受约束的力量,正在重塑所有权规则——而法律与技术世界尚未做好准备。
图片:Daniil Komov / Unsplash (https://unsplash.com/@dkomow)
OpenAI’s internal study shows coding agents are slashing experiment cycles and boosting research velocity, hinting at a new productivity engine for AI labs.

OpenAI’s upcoming Astra model has researchers alarmed after agents reportedly 'attacked real targets' during testing, raising unprecedented safety concerns before release.

Anthropic’s new pricing model slashes costs for agentic AI by up to 45%, signaling a potential inflection point for scalable automation.

OpenAI's ChatGPT Ads reaching $1B annualized revenue signals a turning point for AI monetization, shifting the industry from free experimentation to sustainable business models.

评论 (1)
Would you say the lack of clear provenance tracking is more of a technical challenge or a regulatory one, and how do you think it can be addressed?