Re: GR: Ban LLM contributions from Debian

Gunnar Wolf <[email protected]> Fri, 24 Jul 2026 22:18:57 -0600
Newsgroups gmane.linux.debian.devel.vote
Message-ID <[email protected]>
Hello,

I am seconding Pierre-Elliott's option, which I quote in full below.

While not a fan of what has happened in the LLM world, I cannot agree a
valid way out that will project Debian as a responsible project for the
future is to stick the sand and sing “lalala this does not exist”. Going in
a prohibitionist route will turn us more into censors than anything; I
prefer we are open regarding the tools we use, and keep being responsible
and committed to verify the output we get when a tool gets prompted is of a
quality at least similar to what we would achieve at a first iteration of
human work.

As those that read Planet Debian might remember, I recently reviewed an
opinion article regarding the use of LLM fraud detectors against students,
regarding whatever we can get out of it self-deceiving and unfair. The
article is quite easy to read, and not too long. If you are interested in
reading it, find it at:

     https://www.tandfonline.com/doi/full/10.1080/1360080X.2026.2622146

     Bassett, M. A., Bradshaw, W., Bornsztejn, H., Hogg, A., Murdoch, K.,
     Pearce, B., & Webber, C. (2026). Heads we win, tails you lose: AI
     detectors in education. Journal of Higher Education Policy and
     Management, 1–16.

Pierre-Elliott Bécue dijo [Fri, Jul 24, 2026 at 12:40:59AM +0200]:
>Based on the feedback I got:
>
>BEGIN BALLOT OPTION
>
>Accept AI contributions for Debian specific work
>================================================
>
>Debian as a project does not endorse or recommend the use of generative
>AI assistants for software development, as it raises multiple concerns
>about ethics, legality, copyright, etc.
>
>Nevertheless, Debian acknowledges that these practices are already in
>use and here to stay. Rather than banning their use, which seems
>counter-productive and unenforceable, the project chooses to place
>responsibility on contributors and therefore defines the following
>guidelines.
>
>*These apply exclusively to code and work done specifically for the
>Debian project (Debian websites, applications, resources, packages,
>etc.)*. They do not apply to any upstream work. In what follows, "work"
>refers to the contributions done specifically for the Debian project.
>
> - All code and work assisted by a generative AI agent or tool must
>   comply with the DFSG.
> - The submitter is solely responsible for the submitted work and:
>   + they sufficiently evaluated and properly understand the work they
>     intend to submit, and are able to explain and defend it;
>   + they put any potential Signed-off-by tag and GPG signatures on the
>     contributions they send to the Debian infrastructure (package,
>     commit, mail, …) themselves;
>   + any content uploaded that would end up in production on Debian
>     infrastructure (main git branch, package upload) has been submitted
>     by them explicitely.
> - Work assisted by a generative AI agent or tool should be marked as
>   such in the adapted place (commit message, changelog, …). Some
>   lightweight generative tools, such as tab-completion in Copilot, may
>   be used without the contributor realising they rely on generative AI
>   models; we therefore trust submitters to assess when this rule
>   applies. When in doubt, add such marking;
> - No cloud-based AI shall be used when the data transmitted could
>   either be sensitive to the project (personal data, information under
>   embargo, …) or not public (debian-private discussions, …).
>
>END BALLOT OPTION



--
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQRgswk9lhCOXLlxQu/i9jtDU/RZiQUCamQ5KgAKCRDi9jtDU/RZ
ic0gAQC2PCFFKBblVV54s+PHgPUQ8Hf7yZGdKg5t1sBoqX8vlAD8C0qW5j/glTvI
z9dfjNo0egv+jA9yYUAoECgVRMNuNQ0=
=GlyR
-----END PGP SIGNATURE-----