Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code
ZDNET's key takeaways — Cal is reluctantly moving away from open source for security. — This move isn't about Mythos, but risks from modern AI tools.
ZDNETSteven Vaughan-Nichols
Context & Ripple Effects
Related coverage has focused on AI’s growing role in software production and repository infrastructure: OpenAI is reportedly exploring a GitHub alternative, while Entire is building tools to manage AI-written code. Cal.com’s decision adds a security-driven constraint to that developer-tool shift.
It also contrasts with earlier coverage of Meta using open source to extend its influence in AI. Here, access to source code is being treated less as a distribution advantage and more as an exposure that must be controlled.
First-order effects
Cal.com will restrict access to its core codebase, reducing the ability of outside developers to inspect, contribute to, or reuse that portion of the software.
The company is prioritizing protection from AI-enabled attacks over the collaboration and transparency associated with its prior open-source posture.
Second-order effects
Developers and organizations that depended on the public codebase may need to adjust contribution, integration, or auditing workflows around Cal.com’s software.
The move strengthens the case for repository-management and code-governance tools aimed at handling AI-generated code and AI-assisted security risks.
Third-order effects
If other open-source vendors reach similar conclusions, AI-assisted vulnerability discovery could push more commercial projects toward selective disclosure, dual licensing, or closed core repositories.
That would make trust and access governance a more central competitive variable in developer platforms, even as AI tools make code production and analysis easier to scale.
The trend: AI is changing software development from a primarily productivity-led story into one where code-access policies and security governance become strategic product decisions.
I'm certain this isn't the message they intended to present, but this comes across to me as a company saying “we no longer trust in our own ability to keep your data secure”
This is wrong. Open source isn't dead just because AI can more easily reverse engineer your codebase. AI can reverse engineer your closed source system just as easily. The solution isn't to hide the source. The solution is transparency, publishing advisories, and hardening.
Thinking that going closed source is going to save you from the onset of AI is just delusional tbh. Yes, the world is changing. The answer is to change with it and figure out new ways to succeed, rather than make decisions from a place of fear of losing what you have.
If you look at GPT 5.4-Cyber and it's ability for closed source reverse engineering, I have bad news for you. I do very much feel the pain though, there's hundreds of teams that try to poke holes into @openclaw. Our response has been of rapid iteration and code hardening. Which
Open source is dead. That's not a statement we ever thought we'd make. @calcom was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security [video]
this is what happens when you only use open source as a marketing invective anyway. because the concerns you have about code security don't disappear just because you close the source.