On Wed, Jul 22, 2026 at 09:31:10PM +0200, Lucas Nussbaum wrote: > Hi, > > On 22/07/26 at 17:35 +0200, Matthias Geiger wrote: > > > > Hi all, > > > > What follows is a GR proposal to ban LLM contributions. > > I would like to propose the following ballot option. > > This is the GR proposal from > https://lists.debian.org/debian-vote/2026/02/msg00000.html with > amendments from the discussion back then.
Seconded, I have some notes and observations below. > > BEGIN PROPOSAL > > # Allow AI-Assisted Contributions > > Using its power under Constitution section 4.1 (5), the project issues the > following statement describing its current position on AI-assisted > contributions. This statement describes the position of the project at the > time it is adopted. That position may evolve as time passes without the need > to resort to future general resolutions. The GR process remains available if > the project needs a decision and cannot come to a consensus. > > The Debian project recognizes that AI-assisted contributions raise many > concerns, e.g. about the technical quality and maintainability of such > contributions, and their legal status. AI itself also raises additional > concerns, about its impact on society at large, on the IT industry and on > Free Software; about its environmental impact; and the aggressive or > non-compliant practices of AI scrapers. > > Nevertheless, many Debian contributors find AI tools helpful when > contributing to Debian, and ultimately for improving Debian. > > Given both the benefits and risks of AI assistance, and the controversial > discussions within the community, the Debian project finds it necessary to > clarify its position on AI-assisted contributions and establish clear > guidelines. > > The Debian project allows AI-assisted contributions (partially or fully > generated by an LLM), provided the following conditions are met: > > 1. **Legal Compatibility:** Contributors should ensure that the terms and > conditions of the generative AI tool do not impose contractual > restrictions that conflict with the distribution, modification, or use of > the output in the context of Debian. > > 2. **Licensing and Attribution:** If any pre-existing copyrighted materials > (including pre-existing code licensed as free software) authored or owned > by third parties are included in the AI tool’s output, prior to > contributing such output to the project, the contributor should verify > that such materials are available under a compatible license. > Additionally, the contributor should provide notice and attribution of > such third party rights, along with information about the applicable > license terms, with their contribution. > > 3. **Accountability:** Contributors assume full responsibility for their > contributions, including vouching for the technical merit, security, > license compliance, and utility of their submissions. The contributor > remains solely accountable for the entirety of these contributions. > Contributors should fully understand the proposed changes and be prepared > to justify them. > > 4. **Explicit Disclosure:** When a significant portion of the contribution > is taken from a tool without manual modification, contributors should > disclose the tool's use. This may be recorded using Git trailers, such as > `Generated-By:` or `Assisted-By:`. > > 5. **Prior Discussion of Bulk or Automated Changes:** Similarly to the > mass-bug filing process (Developers Reference section 7.1.1), > contributors should discuss their intention before submitting bulk or > autonomously generated contributions. Any such automated process should > be overseen by a human who remains accountable for its behavior and > output. > > 6. **Community Courtesy:** To respect the preferences of project members who > wish to avoid AI-generated content, contributors should clearly label > such content in mailing list and bug discussions (e.g., by identifying > such content with a clear disclaimer or a machine-readable tag like > `[AI-Generated]`). > > 7. **Confidentiality and Privacy:** Contributors must not use generative AI > tools that transmit data to untrusted providers with non-public or > sensitive project information (such as embargoed security reports or > private communication), as this may lead to the unintended disclosure of > confidential data. > > END PROPOSAL Notes and observations: A. Advertising For 4,5,6 I'd like us to avoid advertising individual companies or products in persistent history such as Git repositories, so I generally believe in "Assisted-By: LLM" as being preferable or record the history only in the merge request. I was arguing last week we should never disclose AI involvement but I think this went to far in the other direction. B. Additional requirements I'm unsure if this GR provides me the means to impose additional requirements on APT contributors to use exclusively open weight models. C. AI review bots on Salsa I'd like to note that yesterday I plugged a "Reviewer" guest-level token into a harness and had it review a bunch of APT merge requests that would not progress without AI review (translations), as well as the ones coming from Canonical. I don't know how I feel about sicking AI reviews on unsuspecting contributors but it stands to reason that AI reviews substantially improve quality and confidence versus me just yolo shipping stuff (or me not shipping the stuff); and it's arguably an improvement in transparency over having the AI review comments just for me It failed to state it was an AI review in half the reviews; but where it did, that disclaimer would be sufficient under my reading of point 6 even if the contributor has no chance to avoid it. -- debian developer - deb.li/jak | jak-linux.org - free software dev ubuntu core developer i speak de, en
signature.asc
Description: PGP signature

