Hi, On 23/07/26 at 13:03 +0200, Stefano Zacchiroli wrote: > The change I'd like to suggest is about the following passage, which I'm > quoting again: > > > 2. **Licensing and Attribution:** If any pre-existing copyrighted materials > > (including pre-existing code licensed as free software) authored or owned > > by third parties are included in the AI tool’s output, prior to > > contributing such output to the project, the contributor should verify > > that such materials are available under a compatible license. > > Additionally, the contributor should provide notice and attribution of > > such third party rights, along with information about the applicable > > license terms, with their contribution. > > The final part, starting at "Additionally" seems to impose an extra burden > wrt usual license obligations, even when the involved license(s) do not > impose it per se. > I hence propose to remove and integrate it in the previous part of point (2), > with something like: > > 2. **Licensing and Attribution:** If any pre-existing copyrighted > materials (including pre-existing code licensed as free software) > authored or owned by third parties are included in the AI tool’s > output, prior to contributing such output to the project, the > contributor should verify [they have the right to submit it under > the relevant open source license]. > > the new part is between "[...]".
Accepted; for reference, the full proposal is provided below # Allow AI-Assisted Contributions Using its power under Constitution section 4.1 (5), the project issues the following statement describing its current position on AI-assisted contributions. This statement describes the position of the project at the time it is adopted. That position may evolve as time passes without the need to resort to future general resolutions. The GR process remains available if the project needs a decision and cannot come to a consensus. The Debian project recognizes that AI-assisted contributions raise many concerns, e.g. about the technical quality and maintainability of such contributions, and their legal status. AI itself also raises additional concerns, about its impact on society at large, on the IT industry and on Free Software; about its environmental impact; and the aggressive or non-compliant practices of AI scrapers. Nevertheless, many Debian contributors find AI tools helpful when contributing to Debian, and ultimately for improving Debian. Given both the benefits and risks of AI assistance, and the controversial discussions within the community, the Debian project finds it necessary to clarify its position on AI-assisted contributions and establish clear guidelines. The Debian project allows AI-assisted contributions (partially or fully generated by an LLM), provided the following conditions are met: 1. **Tooling Legal Compatibility:** Contributors should ensure that the terms and conditions of the generative AI tool do not impose contractual restrictions that conflict with the distribution, modification, or use of the output in the context of Debian. 2. **Licensing and Attribution:** If any pre-existing copyrighted materials (including pre-existing code licensed as free software) authored or owned by third parties are included in the AI tool’s output, prior to contributing such output to the project, the contributor should verify they have the right to submit it under the relevant open source license. 3. **Accountability:** Contributors assume full responsibility for their contributions, including vouching for the technical merit, security, license compliance, and utility of their submissions. The contributor remains solely accountable for the entirety of these contributions. Contributors should fully understand the proposed changes and be prepared to justify them. 4. **Explicit Disclosure:** When a significant portion of the contribution is taken from a tool without manual modification, contributors should disclose the tool's use. This may be recorded using Git trailers, such as `Generated-By:` or `Assisted-By:`. 5. **Prior Discussion of Bulk or Automated Changes:** Similarly to the mass-bug filing process (Developers Reference section 7.1.1), contributors should discuss their intention before submitting bulk or autonomously generated contributions. Any such automated process should be overseen by a human who remains accountable for its behavior and output. 6. **Community Courtesy:** To respect the preferences of project members who wish to avoid AI-generated content, contributors should clearly label such content in mailing list and bug discussions (e.g., by identifying such content with a clear disclaimer or a machine-readable tag like `[AI-Generated]`). 7. **Confidentiality and Privacy:** Contributors must not use generative AI tools that transmit data to untrusted providers with non-public or sensitive project information (such as embargoed security reports or private communication), as this may lead to the unintended disclosure of confidential data. - Lucas
signature.asc
Description: PGP signature

