Re: Ballot option: Allow AI-Assisted Contributions

Stefano Zacchiroli <[email protected]>
Newsgroups gmane.linux.debian.devel.vote
Message-ID <rgbaapmzhiiiaimgaghsytceoos7atit65fgr76jlcqi3ihi7l@m4zdxbw7icuy>
With this message I'd like to: (1) second Lucas' proposal below, because I think it's important to have an option that goes in this direction on the ballot, and (2) propose a minor change to the text, which I hope Lucas can accept.

On Wed, Jul 22, 2026 at 09:31:10PM +0200, Lucas Nussbaum wrote:
> BEGIN PROPOSAL
> 
> # Allow AI-Assisted Contributions
> 
> Using its power under Constitution section 4.1 (5), the project issues the
> following statement describing its current position on AI-assisted
> contributions. This statement describes the position of the project at the
> time it is adopted. That position may evolve as time passes without the need
> to resort to future general resolutions. The GR process remains available if
> the project needs a decision and cannot come to a consensus.
> 
> The Debian project recognizes that AI-assisted contributions raise many
> concerns, e.g. about the technical quality and maintainability of such
> contributions, and their legal status. AI itself also raises additional
> concerns, about its impact on society at large, on the IT industry and on
> Free Software; about its environmental impact; and the aggressive or
> non-compliant practices of AI scrapers.
> 
> Nevertheless, many Debian contributors find AI tools helpful when
> contributing to Debian, and ultimately for improving Debian.
> 
> Given both the benefits and risks of AI assistance, and the controversial
> discussions within the community, the Debian project finds it necessary to
> clarify its position on AI-assisted contributions and establish clear
> guidelines.
> 
> The Debian project allows AI-assisted contributions (partially or fully
> generated by an LLM), provided the following conditions are met:
> 
> 1. **Legal Compatibility:** Contributors should ensure that the terms and
>    conditions of the generative AI tool do not impose contractual
>    restrictions that conflict with the distribution, modification, or use of
>    the output in the context of Debian.
> 
> 2. **Licensing and Attribution:** If any pre-existing copyrighted materials
>    (including pre-existing code licensed as free software) authored or owned
>    by third parties are included in the AI tool’s output, prior to
>    contributing such output to the project, the contributor should verify
>    that such materials are available under a compatible license.
>    Additionally, the contributor should provide notice and attribution of
>    such third party rights, along with information about the applicable
>    license terms, with their contribution.
> 
> 3. **Accountability:** Contributors assume full responsibility for their
>    contributions, including vouching for the technical merit, security,
>    license compliance, and utility of their submissions. The contributor
>    remains solely accountable for the entirety of these contributions.
>    Contributors should fully understand the proposed changes and be prepared
>    to justify them.
> 
> 4. **Explicit Disclosure:** When a significant portion of the contribution
>    is taken from a tool without manual modification, contributors should
>    disclose the tool's use. This may be recorded using Git trailers, such as
>    `Generated-By:` or `Assisted-By:`.
> 
> 5. **Prior Discussion of Bulk or Automated Changes:** Similarly to the
>    mass-bug filing process (Developers Reference section 7.1.1),
>    contributors should discuss their intention before submitting bulk or
>    autonomously generated contributions. Any such automated process should
>    be overseen by a human who remains accountable for its behavior and
>    output.
> 
> 6. **Community Courtesy:** To respect the preferences of project members who
>    wish to avoid AI-generated content, contributors should clearly label
>    such content in mailing list and bug discussions (e.g., by identifying
>    such content with a clear disclaimer or a machine-readable tag like
>    `[AI-Generated]`).
> 
> 7. **Confidentiality and Privacy:** Contributors must not use generative AI
>    tools that transmit data to untrusted providers with non-public or
>    sensitive project information (such as embargoed security reports or
>    private communication), as this may lead to the unintended disclosure of
>    confidential data.
> 
> END PROPOSAL

I second the above proposal.

The change I'd like to suggest is about the following passage, which I'm quoting again:

> 2. **Licensing and Attribution:** If any pre-existing copyrighted materials
>    (including pre-existing code licensed as free software) authored or owned
>    by third parties are included in the AI tool’s output, prior to
>    contributing such output to the project, the contributor should verify
>    that such materials are available under a compatible license.
>    Additionally, the contributor should provide notice and attribution of
>    such third party rights, along with information about the applicable
>    license terms, with their contribution.

The final part, starting at "Additionally" seems to impose an extra burden wrt usual license obligations, even when the involved license(s) do not impose it per se.
I hence propose to remove and integrate it in the previous part of point (2), with something like:

  2. **Licensing and Attribution:** If any pre-existing copyrighted
     materials (including pre-existing code licensed as free software)
     authored or owned by third parties are included in the AI tool’s
     output, prior to contributing such output to the project, the
     contributor should verify [they have the right to submit it under
     the relevant open source license].

the new part is between "[...]".

Cheers
-- 
Stefano Zacchiroli - https://upsilon.cc/zack
Full professor of Computer Science, Polytechnic Institute of Paris
Co-founder & Chief scientific officer Software Heritage
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEE8ZooXsFA+JEz681OfH5Cj5NBJ5kFAmph9O4ACgkQfH5Cj5NB
J5lCPA/9GVcOdrVT9MoYjUGQSwiW3JZyKLjhl6Ub8sX6HtH2jLnMw/l+k0xJMXxr
BDodDdjRN6GNu/Kza2GuQxBietEgH6+2vdt1wPolU15eOTCRar67IeQrOXdHpeMz
nwjI/5PXUoRjlgtNMNSfxSdwKDmyZc2YZ/NCSpS5OE3YjomcTKTAd3Gsc1nQFZ8U
evUFSlLRUkZIcl9mmJK3PYYadXzlCTW0ujQ4Q91ZFIuMmMeazWi5nImJ8+kGbh0X
YnMAgv5gBkJjz289MX7fyWqXwU26faQeDwDqMCs532CnWvb5ENrv0iLhlptDTvuv
vxQAdFPR16rGH2e+WAWUfG0qxJGZ6uiiPPZ/k02mqM5uhZdIlcJ/9Xax1fCCMe0b
AFKrwF8+op+iYrCX4gdpPTo/M8NUsQC8ibc9aKnM2qSoLWi8TxOhyQVKfEmIq9U+
hjfeSMntykZ2fM9sLMkqzeU7rb7Nb3Uhpu/8vkmn9KMSRkYBHFdEJvN8xzfPNAU0
fyJ0B82RSTbrycQHc6c5rEVaVGdY0STZSFQUQN9JWLYgKwSgeSRjs3CuoqMUF8Q0
pQSspmxQp96pqeQurYJqDZzIsu+w+ZqwqcM+iBDw/71W9YSS+YVybki+FDR9qxO6
Okw4EFXwNy8UKDKEMj6vBRbmqO0fVshi1qRqXhyVcmebjICn6HA=
=bB8H
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.