Debian Just Decided AI Code Is the Human's Problem

Debian has finished the loudest AI argument in free software, and the winning policy is a masterclass in saying nothing with enormous force. The project's General Resolution on LLM usage closed on August 28 with a field that included an outright ban on AI-assisted contributions, and the ban died ugly: amending the Social Contract needed a three-to-one supermajority, and it finished at a ratio of 0.560. The winner, “Responsible Use of Generative AI,” took roughly 575 ballots from 425 unique voters, and it opens with the most Debian sentence possible: “Debian neither endorses nor prohibits the use of generative AI tools.” For a project that once had to vote on what its project lead was called, that non-endorsement is the strong position, and it's worth parsing because the part that says nothing is doing the heavy lifting.

The part that has teeth is the responsibility clause. Every contribution, “regardless of how and with which tools they were produced,” must satisfy the same standards of quality, correctness, maintainability, and legal compliance. The resolution even names the failure mode out loud: “Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian's established development practices.” Contributors are expected to understand, review, test, and modify AI-assisted output before it ships; disclosure of AI assistance is encouraged but not required; and feeding confidential or security-sensitive information to third-party AI services is explicitly out. Notably, the resolution deliberately declines to take a position on whether AI output is copyrightable — the legal status of machine-written code remains an open question it refuses to settle, and the whole thing is issued as a position statement under Constitution 4.1(5), so it can evolve later without another vote. The ban camp didn't just lose a ballot; it lost the jurisdiction. And for context, Debian isn't following a ban it disagrees with so much as standing out from one: Gentoo and NetBSD both now forbid AI-assisted contributions, and the winning text borrows its shape from GCC's AI policy and rust-lang's LLM usage policy. The largest free Linux distribution just chose the middle lane while the rest of the distribution world picked a side.

Graphical rendering of the results
Source image 1

Here's why the non-policy is actually a policy. It moves the entire quality question from the community to the contributor. There is no new tool to detect AI code, no new disclosure field to fill in, no metadata to track. The check on every AI-assisted line of code that lands in Debian is the same check that always existed: a human maintainer who claims to have reviewed it. That's the same verification gap I've been staring at for weeks — GitHub's commit curve just doubled in four months while review capacity stayed human-paced, and now one of the most important Linux projects has codified the answer to “who checks AI code?”: the person who typed it in, under the same standards as anyone else, with the project explicitly declining to audit them. One contributor announced they're quitting over the outcome, and they're not wrong that “same standards” is a phrase doing a lot of work when the standards were written for code a human actually looked at. I'm not sure I'd do it differently — a ban would have been unenforceable theater, and disclosure-only is what y

Source article image
Source image 2
ou do when you trust your reviewers. But trust is the load-bearing wall, and the wall is now carrying a much heavier building. If your team is already merging AI-generated contributions, what's your actual line between “reviewed” and “rubber-stamped”? Because Debian just made the human's answer the only one that matters.

Sources

Comments

  1. The sad thing is that critical articles like yours are very scarce. The mainstream tech media is captured and just praises the "neutral" stance, which you have exposed as "non-neutral".

    Debian is now officially an appendix of Canonical, xAI, Anthropic, OpenAI and Microsoft. The decline of a project that started as a moral opposition to Microsoft and Sun is unbelievable.

    Ironically, the Canonical people who voted for this will be the first to be fired once Debian is fully automated.

    ReplyDelete

Post a Comment

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door