Re: Draft permissive ballot option (was: GR: Ban LLM contributions from Debian)

Marc Haber <[email protected]> Sun, 26 Jul 2026 17:04:50 +0200
Newsgroups gmane.linux.debian.devel.vote
Message-ID <[email protected]>
Hi,

On Sun, Jul 26, 2026 at 10:27:08AM +0200, Ansgar 🙀 wrote:
>On Sun, 2026-07-26 at 09:11 +0200, Marc Haber wrote:
>> We expect
>> our contributors to design their workflows with due dilience, and to
>> keep AI tools away from confidential materials, private comunications
>> and cryptographic keys regarding the Debian infrastructure and
>> community.
>
>I suggest to leave out this part: if you already trust cloud providers
>like Riseup or Google with that private communication, say mails to d-
>private@, then it probably doesn't matter whether you trust them just
>for mail processing or also for AI services.  I'm also not sure how
>realistic it is to completely avoid AI tools with those providers?

I think the "realistic" part is what gets me to follow your advice here. 
In my opinion, especially Gmail has no place to host a Debian 
Developer's Mailbox, its interface is quite clearly unsuitable to 
properly participate in complicated mailing list threads and Google 
is quite obviously uninterested in free information exchange with the 
"Open Internet". I mean, they're putting up arbitrary rules about how 
may send mail to their customers while remaining the number one source 
of Unsolicited E-Mail over years.

But that probbably is another war field.

I am concerned however that people would not vote for a permissive 
version if the "keep confidential things and credentials off AI tools" 
is not present.

Actually that paragraph is what I wrote without AI assistand and put it 
in place just before posting.

>Maybe it should also include a reminder that larger automated actions
>like mass-bug filing should have prior discussion.

Yes. Agreed. I am open to wording suggestions. 

the generative AI tool suggests:


-----
Contributors are expected to exercise appropriate care when designing 
workflows that incorporate generative AI tools. In particular, they 
should ensure that confidential information, private communications, 
security-sensitive information, cryptographic keys, credentials, and 
other non-public material relating to the Debian Project, its 
infrastructure, or its community are not disclosed to third-party AI 
services unless such disclosure has been explicitly authorized and is 
consistent with Debian's security and privacy requirements.

The use of generative AI does not alter Debian's established 
expectations regarding large-scale or automated project actions. 
Contributors intending to perform actions with broad project impact, 
such as mass bug filing, large-scale code modifications, or other 
automated changes affecting many packages or contributors, should seek 
prior discussion and consensus through the appropriate project channels 
before proceeding.
-----

and I happen to like that

Greetings
Marc