Hello Lucas,

Thanks for adding this ballot.
I have a question and a few comments if you don't mind.

[...]

> 
> 4. **Explicit Disclosure:** When a significant portion of the contribution
>    is taken from a tool without manual modification, contributors should
>    disclose the tool's use. This may be recorded using Git trailers, such as
>    `Generated-By:` or `Assisted-By:`.

I'd avoid proposing the tool here. I fear our commits will be infected by badly
intended promotion of this or that tool. Perhaps you could rephrase it a bit to
encourage the disclosure of AI usage, without mentioning the tool behind it
specifically?

> 5. **Prior Discussion of Bulk or Automated Changes:** Similarly to the
>    mass-bug filing process (Developers Reference section 7.1.1),
>    contributors should discuss their intention before submitting bulk or
>    autonomously generated contributions. Any such automated process should
>    be overseen by a human who remains accountable for its behavior and
>    output.
> 
> 6. **Community Courtesy:** To respect the preferences of project members who
>    wish to avoid AI-generated content, contributors should clearly label
>    such content in mailing list and bug discussions (e.g., by identifying
>    such content with a clear disclaimer or a machine-readable tag like
>    `[AI-Generated]`).

My feeling is that the above will legitimise the use of 'AI-generated' content
in your mailing lists and the BTS. Experience has shown that this usually
triggers a wave of negative reactions that I'd rather avoid. I'd actually argue
for merging 4 and 6 by making it clear that AI-generated or heavily assisted
content is never accepted in Debian without disclosure, without enforcing any
specific means or mentioning any specific areas (mailing lists, bts, salsa,
etc.) where this should be applied.

> 7. **Confidentiality and Privacy:** Contributors must not use generative AI
>    tools that transmit data to untrusted providers with non-public or
>    sensitive project information (such as embargoed security reports or
>    private communication), as this may lead to the unintended disclosure of
>    confidential data.

By 'untrusted providers' do you mean anything != *.d.o ? Shouldn't it be more
clear?

Bests,

-- 
Tiago Bortoletto Vaz

Attachment: signature.asc
Description: PGP signature

Reply via email to