Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code
ZDNETSteven Vaughan-Nichols
Context & Ripple Effects
Cal.com’s move sits alongside a growing focus on the security and operational control of AI-assisted software development. Related coverage includes a new company aimed at managing AI-written code and OpenAI’s reported work on a GitHub alternative after engineering outages.
The immediate significance is not scheduling software itself but a formerly open core codebase being treated as an attack surface in an era of AI-enabled code discovery and exploitation.
First-order effects
Cal.com will restrict access to its core repository, reducing public visibility into and participation in the code it previously maintained openly.
Its developers and security team gain tighter control over repository access and disclosure while prioritizing protection against the cited AI-enabled hacking risk.
Second-order effects
Open-source projects handling valuable production software may reassess whether public repositories expose too much implementation detail as AI tools make code analysis and attack preparation easier.
Demand can shift toward developer platforms and code-management tools that combine AI-assisted development with stronger repository controls, auditability, and resilience.
Third-order effects
If more projects close formerly open cores, the AI coding boom could make software-development infrastructure more centralized: collaboration remains valuable, but access to the underlying code becomes more selectively governed.
That would sharpen the trade-off between open-source transparency and security, with the eventual balance depending on whether AI-driven attacks outpace the defensive value of public review.
The trend: AI is turning source-code access and developer tooling into a more contested security-control layer, rather than a purely collaborative one.
Open source is dead. That's not a statement we ever thought we'd make. @calcom was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security [video]
This is wrong. Open source isn't dead just because AI can more easily reverse engineer your codebase. AI can reverse engineer your closed source system just as easily. The solution isn't to hide the source. The solution is transparency, publishing advisories, and hardening.
this is what happens when you only use open source as a marketing invective anyway. because the concerns you have about code security don't disappear just because you close the source.
Thinking that going closed source is going to save you from the onset of AI is just delusional tbh. Yes, the world is changing. The answer is to change with it and figure out new ways to succeed, rather than make decisions from a place of fear of losing what you have.
If you look at GPT 5.4-Cyber and it's ability for closed source reverse engineering, I have bad news for you. I do very much feel the pain though, there's hundreds of teams that try to poke holes into @openclaw. Our response has been of rapid iteration and code hardening. Which
I'm certain this isn't the message they intended to present, but this comes across to me as a company saying “we no longer trust in our own ability to keep your data secure”