Re: GR: Ban LLM contributions from Debian

Pierre-Elliott Bécue <[email protected]> Fri, 24 Jul 2026 01:09:32 +0200
Newsgroups gmane.linux.debian.devel.vote
Message-ID <[email protected]>
Seconded

(this GR needs a representative set of options)

Matthias Geiger <[email protected]> wrote on 22/07/2026 at 17:35:37+0200:

> Hi all,
>
> What follows is a GR proposal to ban LLM contributions.
>
> It is time for Debian to make a statement regarding generative AI and LLM usage.
> Since this has been discussed in exhaustive detail on -private and -project,
> the proposal follows below without any further discussion.
>
>
> BEGIN PROPOSAL
>
>
> Preamble
> ===========
>
> This proposal aims to expressly forbid any contributions to Debian written with
> the use or assistance of large language models (LLMs) or other generative AI tools.
>
> The scope of this GR is (non-exhaustive): - Debian source packages
> - Official Debian project software, such as lintian
> - Debian web resources - Documentation and translations added by Debian
>  contributors
> - Official communication from Debian
>
> It does not include: - Upstream projects using LLMs for development
> - AI-related software
>
>
> Rationale
> ===========
>
> Debian has a well-earned reputation for stability. This stability is crucial to
> Debian's position in the free software ecosystem. It is our belief that
> widespread LLM usage comes from the "move fast, and break things" attitude that,
> while common in many parts of this industry, is contrary to what makes Debian
> Debian, and is inappropriate for Debian contributors. In practical terms, LLM
> usage raises the following concerns: 1. Copyright      LLM output has very
> unclear legal status: it may be possible to copyright on its own merits, or not;
> it may be affected by all of the licenses and copyrights in the training data,
> or not.     Debian Policy and the DFSG require absolute clarity for licensing
> and copyright[1][2]. Software and other contributions written conventionally by
> humans with unclear copyright or license 	status are not allowed in Debian;
>    LLM output should not have a special exception to this.
>    2. Quality  LLM output has many well-known problems with
>    accuracy.[3][4][5] A LLM can never "know" if its output is correct 	since it
>    merely produces syntactically likely combinations of the 	training data.
>    In some environments this is good enough. In Debian, it is not. For instance,
>    in packaging, each Debian source package is unique. Since packaging syntax
>    and best practices have changed over time,     a LLM-produced package will
>    have a mixture of contents spanning the age of the archive, with watch files
>    that do not work, overrides out of context, imaginary copyright, 	and will
>    generally be unfit for upload.     A seasoned Debian contributor with
>    packaging expertise may find some limited usefulness here, but a new
>    contributor cannot, and would not know how to fix it.     These same quality
>   and accuracy concerns apply clearly to all of the areas listed in the scope
>   of this proposal above.
>    If Debian were a closed organization comprising only domain experts who never leave, this might not be an issue; however,
>        3. Community      Debian is a project that is more than just code: it is
>        a community built on shared interests in free software and solving
>        technical problems.     Debian intentionally grows this community through
>        many means, and new contributors are always encouraged to join. Allowing
>        LLM contributions breaks this.     New contributors submitting LLM output
>        for review places an unnecessary strain on the reviewer, which can lead
>        to burnout. Furthermore, LLM-dependent new contributors     do not
>        actually learn and understand the details of Debian packaging or
>        processes, so they cannot come to replace a former burned out DD. 4.
>        Ethics      LLM companies directly hurt the free software community as
>       whole by scraping the whole web for training data without any regard for
>       license, copyright, or even established
>    conventions such as robots.txt.[6]
>    This has had a major negative impact on Debian's public web resources, effectively a large scale and perpetual Denial of Service attack on sites that many users rely on.
>    As a consequence parts of our infrastructure were not reachable at all, and
>    JS-based checks had to be enabled. Many other projects were similarly
>    affected.     Furthermore, LLM training consumes a staggering amount of
>   resources[7], and the user verification systems that we have been forced to
>   implement as protection waste resources as well.
>    This is blatant disregard for the internet as a public resource, wastes
>    system administrator time, and although individual LLM sessions do not
>    directly use massive resources or DoS the public web,     the fact that they
>    can be used at all is a direct result of these unethical behaviours by the
>    LLM companies. Debian has a Social Contract. [8] Our priorities are our users
>   and free software.
> Debian is Stable. [9] Users and organizations choose Debian because it is reliable and secure.
>
> Debian is not here to generate as much code as possible requiring manual review
> by a shrinking number of human volunteers, or to package every piece of
> software, or to rush new features, but these are what LLMs are used for. In
> conclusion, allowing LLM contributions is contrary to the social contract and
> the common cause of creating a free operating system with a focus on quality and
> stability.
>
>
> Proposal
> ===========
>
> In the interest of not eroding Debian's reputation or further damaging the
> community, LLM-assisted contributions should be prohibited from inclusion in
> Debian. Though our position is that LLM contributions are contrary to documents
> already ratified by Debian, in order to remove all doubt, we propose the
> following addition to the Social Contract: 6. Works Created through the use of
> Large Language Models (LLMs)
>    We will not allow direct contributions to Debian written with the use or assistance
>    of large language models (LLMs) or other generative AI tools. Direct contributions are
>    defined as packaging, native Debian software like lintian, documentation and translations
>    written by Debian contributors, and official Debian web resources, etc. Other categories
>    such as upstream projects written with LLM assistance may be included at a
>    later date.     This ensures that Debian remains a stable, trusted, and
>   reliable operating
>    system, and protects the interests of the Debian volunteers who make it possible.
>    Possible Issues
> ===========
>
> Other projects exploring similar decisions have elicited a common reply: "How will you enforce a ban on LLM contributions?"
> While enforcement could be a challenge, this is a statement of intent by the
> Debian community, and we trust this community to adhere to it in good faith.
>
> END PROPOSAL
>
>
> Citations
> ===========
> [1] https://www.debian.org/doc/debian-policy/ch-archive.html#copyright-considerations
> [2] https://www.debian.org/social_contract#guidelines
> [3] https://web.archive.org/web/20240614004123/https://news.northeastern.edu/2023/11/10/ai-chatbot-hallucinations/
> [4] https://web.archive.org/web/20250328154700/https://transformer-circuits.pub/2025/attribution-graphs/biology.html#dives-cot
> [5] https://www.marketwatch.com/story/openais-sam-altman-tells-salesforces-marc-benioff-that-ai-hallucinations-are-more-feature-than-bug-1c035c52
> [6] https://lwn.net/Articles/1008897/
> [7] https://tech-insider.org/ai-data-center-power-crisis-2026/
> [8] https://www.debian.org/social_contract
> [9] https://www.debian.org/doc/manuals/debian-reference/pr01.en.html#_what_is_debian
>
>
> Disclaimers
> ===========
> - Citations are for background information only and do not reflect an endorsement of specific websites.
> - Some ideas and wording were derived from the sources below.
>
>
> Sources
> ===========
> GNOME discussion: https://discourse.gnome.org/t/loupe-no-longer-allows-generative-ai-contributions/27327 (CC0)
> Gentoo AI policy: https://wiki.gentoo.org/wiki/Project:Council/AI_policy
> Codeberg AI policy:
> https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434
>
> This document was written by Matthias Geiger <werdahias> and Jesse Rhodes <sney> with input from Sledge and josch, organically and without language model assistance.
>
>
>
> best,
signature.asc (application/pgp-signature, 853 B)
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEE5CQeth7uIW7ehIz87iFbn7jEWwsFAmpinywPHHBlYkBkZWJp
YW4ub3JnAAoJEO4hW5+4xFsLwGEP/RK+8z6aYYhEebqvSDK2V2sv18TbkV5usJ1R
HEYvOgPaN2gczHqj0wt2A4X31uPXAzgE+wVwiUfFShjwh4MrEuBiO3L7EWySqSC0
k8qwGWydUa8akdNoQV570f6eCAvWDVH7oJpQJM5YgfIFDFICyy9NjaFHiGzsJ8Hr
U2A6evMK0YaPhgDMWPV2fd3w1k/yYVtDsDIBRLPht+IDboE6wxWHu0t3fPkkoZBH
TlIFieFPshdowGbeqWadB6p3DnMBVGwtzZxTpGC6FL1Aw3KeqUnSj5/5Cg8nWQKd
ogJBVbLaVPnzRNWLkPC7Qt7jxJVK555IUVoAGG4TfjAOJgOKGiYxnZumr4pefVyv
bsNMYQmtU3nbG3ivRiwJK+n8MinFc5c7VO0GZ9Yb6sw7km/amLXB59U+ctMve/zc
GZ4JBw3OKZWoXNSi0GumSzi24BaNQuBOFKQVmko1yYj+V4/w0krDhV/rciGtn5+I
yc1W7oIWuaRgtR8tFiUUlDYuvszsTlDoNZ+vWW2SR5245P4mNq+M2AjAuB2RlKu9
ZcRWfPYZOWgxJk2HfxTidYQVE3uZ10unpoavUWlDAZZTN7dUKw5NY9ON9nMlmSCS
iSzak7yiWZl2u5bs7F/4uEbo5vNh61EZt0CjhD7Y6102dSLoQ1pDSEZNVfw5lmMB
PMsjn9gp
=TM8Z
-----END PGP SIGNATURE-----