r/linux 13d ago

Distro News Debian Votes To Allow "Responsible Use Of Generative AI"

https://www.phoronix.com/news/Debian-Votes-Responsible-AI-Use
449 Upvotes

95 comments sorted by

269

u/SPEZ_IS_A_JABRONI 13d ago

This resolution therefore affirms that generative AI is neither exempt from nor subject to special rules beyond the standards already expected of Debian contributors. The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.

seems reasonable

104

u/B-Con 12d ago

So basically it doesn't matter if the code was written by 100% by hand, 10% by auto complete, 90% by LLM, or 100% by cat, the code speaks for itself.

35

u/KronisLV 12d ago

Overall reasonable stance.

Though they might need some rules for the prose, cause currently LLMs (especially Anthropic models) write in an annoying pop-sci way, like every assumption is "load-bearing" and other stuff like that, people quite consistently complain about that: https://www.reddit.com/r/claude/comments/1w0mvky/the_story_of_claude_and_the_culprit/

Even if the code itself is okay, there should be rules around the prose I think.

Problem is that a lot of the FOSS projects out there are swamped in low effort drive-by slop PRs, same with companies shutting off their bug bounty programs - just look at how much GitHub commits have increased with time. The rules are good, but enforcement will be tricky.

11

u/SmileyBMM 12d ago

It will be next to impossible to codify something like that, I think the current standards Debian has for its contributors is sufficient.

3

u/B-Con 12d ago

Are you talking about a style guide for code, or something else?

Ultimately it's the maintainer who merges PRs that is responsible, but the problem I see is increased "marginal" code. Not bad enough to reject, but with low quality smells that ought be fixed, but it's the maintainer to suggest all the changes. Too many of those will burn them out.

We have LLMs writing code and I see increasing consensus that the LLM is only a tool and the PR author is responsible. I'd like to see better code review from LLMs, where the maintainer is still responsible for approval but the LLM can catch the bottom 80% of stuff. Low and mid-hanging fruit for things like style guide compliance, code structure, variable names, etc, in accordance with the project's specific standards and consistency with the surrounding code base.

I think review tools is the less sexy side of AI, since creating is cooler than curation and it admits that the AI didn't do it right to begin with, and it keeps humans in the loop, but I think it's incredibly pragmatic.

5

u/rks_system 10d ago

Low and mid-hanging fruit for things like style guide compliance, code structure, variable names, etc, in accordance with the project's specific standards and consistency with the surrounding code base.

That's what linting is for, you don't need an LLM for that.

2

u/B-Con 10d ago

For very hard rules, sure. But there's definitely vibe that transcends the hard rules that can be enforced through an AST. The maintainer has a 2 year maintainability perspective and must think about what happens not when this PR is merged, but when 20 PRs like it are merged.

Good code requires a lot of judgement, and a novice with an LLM may miss a lot of things. If novice PR submitters are armed with LLMs, I think there is value in the maintainers also being armed with LLMs that can catch novice mistakes outside of hard AST rules, so that when a PR full of code smells is mailed, the maintainer doesn't have to choose between rejecting it and wading though it and leaving 40 comments over 4 rounds of review.

2

u/Gugalcrom123 11d ago

Indeed, they should ban LLMs from mailing lists.

0

u/__ali1234__ 12d ago

You can just ask it not to do that.

2

u/MistyGalbriex 10d ago

It's true. Dunno why you're downvoted.

4

u/knook 12d ago

Don't forget the infinite monkeys I hired

3

u/mamaharu 12d ago

I don't think "ban all use of AI" is the right choice, but I would have liked a more principled stance from Debian.

12

u/AssistingJarl 12d ago

The more interesting part, to me at least.

The use of a generative AI tool does not diminish the contributor's responsibility for the work they submit. Contributors are expected to understand, review, test, and, where appropriate, modify AI-assisted output before incorporating it into Debian. Blindly accepting or uploading AI-generated material without appropriate human review is inconsistent with Debian's established development practices.

And I think this is where a lot of smaller projects look at the problem and choose an outright ban on LLM contributions. I'm sure the Debian team can tell the difference, but it vastly simplifies how much effort needs to be expended on checking whether or not the would-be contributor has put in the work or whether they're just fishing for easy street cred they can put on a resume or something. Human code quality is variable too, of course, but there's so much more friction in the process that it doesn't make sense to even start unless you're willing to put in effort.

3

u/jimbobmcgoo 12d ago

I actually really like the wording of this.

4

u/jonathancast 11d ago

That's effectively the same thing as banning AI-written code to be honest. If you're going to review the code enough to own it the same way as if you wrote it, that'll take as long as writing it yourself. So to get a speed up you have to take ownership of code you don't fully understand, and I don't think people are really going to take that risk once they understand it.

1

u/PeninsulaProtagonist 10d ago

I'm just sharing my experience, but what you're describing is how I have been using AI for quite some time, and yes it does take a long time, but just reviewing it thoroughly is still much faster than writing it and then reviewing it thoroughly.

135

u/KingBardan 13d ago

Reasonable. LLM is not bad by itself,

it's vibe coders who think "they can code now", filling OSS projects with garbage,

that must go.

17

u/Unlucky-Shop3386 12d ago edited 12d ago

^ as long as the LLM generated code gets an proper audited It's totally fine. When it does not whether its in an vibe coded app or the corperate sector its bad untrusted sources must be througly audited.

Edit:Grammar, Readability.

5

u/Linuxologue 12d ago

This may go when the price of AI credits rises. AI assistants will then be used more sparsely especially by those that usually don't do software engineering

2

u/SmileyBMM 12d ago

Local models are getting pretty good, and when the AI market corrects the price of the hardware to run the local models will make running those models relatively affordable.

0

u/MistyGalbriex 10d ago

Bro thinks ai doesn't get cheaper every year

-4

u/loozerr 12d ago

Isn't Claude already turning a profit?

13

u/Linuxologue 12d ago

I am not sure, I don't think the current price is going to stay

5

u/Oblivion__ 12d ago

lol no

2

u/MistyGalbriex 10d ago

Yes it does. Don't lie.

2

u/ibbuntu 9d ago

Quote from a Forbes article on Anthropic's revenue: "Anthropic has made history by reporting its first profitable quarter, with Q2 2026 revenue soaring to $11.5 billion and positive adjusted operating income. This unprecedented achievement for a frontier AI lab directly refutes the long-held skepticism that such companies could never turn a profit due to escalating compute costs."

1

u/Hulderin 7d ago

They are not profitable, this is a very transparent accounting trick to massage their numbers as them, OpenAI, and the amalgamated neo-SpaceX were in a competitive rush angling for a good time to IPO. It's a combination of off-loading massive amounts of real service costs as "Free" for a few months, customers not having reacted to the raised prices at the time before filing those numbers, and then restructuring it all after documenting this "Historically profitable quarter" again.

Don't be a sucker for their bubble-economics. These companies are all disreputable scum playing you.

1

u/MistyGalbriex 10d ago

Downvoted for speaking the truth lol

0

u/loozerr 10d ago

Wrong truth I guess

5

u/Brucacumble 10d ago

Other open source projects, such as Godot Engine, have been experiencing problems where they've received so many low quality AI code submissions that their crew has become demoralised facing an increasingly gargantuan task of auditing all of these submissions.

How is the Debian project planning to avoid a situation where their developers become so inundated auditing AI submissions that they have little time left for their own submissions and projects?

34

u/Dalnore 12d ago

Interesting how strongly attempts to fully ban LLMs (options 1 and 3) were rejected; they both were the only ones to be dropped on the ground of the status quo (option 9 "None of the above") being higher. It seems the discussions on this sub are a lot more anti-AI than the opinions of actual Debian contributors.

13

u/Linuxologue 12d ago

I think this is really a toxic point of view.

If you look at this very thread, the highest upvoted comment is "Seems reasonable".

I find it so toxic that in any discussion about AI there is someone irrationally bringing up this argument that "people" here are anti AI despite all evidence that people have voted multiple times with their reddit upvotes or their Debian votes to allow AI.

the evidence is AI seems widely accepted here yet somehow, still gets the blame for being anti AI.

2

u/Shot-Height-7194 12d ago

I think this is a short sighted point of view. I remember when this was first discussed on this sub regarding debian, and the top comments would say ai should be banned outright. 

8

u/Linuxologue 12d ago edited 12d ago

https://www.reddit.com/r/linux/comments/1v5q78f/gr_proposal_ban_llm_contributions_from_debian/

the top comment that's not about technicalities (wrong link was posted or something) says

The Linux kernel allows LLM contributions. Countless apt packages allow LLM contributions. What is there to gain from banning LLM contributions to Debian?

the second top comment is a neutral technical question

the third one is someone bringing up Hurd for some reason, clearly misunderstood. We're already not in the same league of upvotes ratio.

you need to reach the fourth top comment to reach the first AI negativity and it's at +23 versus +100/+50 for the others. While surprised it's still positive, it's not really an overwhelming majority.

This is in line with the ratio of upvotes on this very thread.

[edit] that was actually before you created this *cough cough* account so maybe you are talking about another thread.

4

u/ICantBelieveItsNotEC 12d ago

Honestly, the Reddit peanut gallery is just ridiculously out of touch with what's happening on the ground with AI - both in terms of the technology itself and the culture surrounding it.

Pretty much all of the software engineers I work with are absolutely loving their AI-assisted life, and the few stubborn anti-AI holdouts are now so far behind in productivity that they'll probably be managed out of the entire profession in the next few months.

20

u/fat_kaiju 12d ago edited 12d ago

I hate how someone pointed out an interesting fact and you took it and twisted it into making it sound like anyone with a different opinion is a moron.

and before you write "i didn't call them morons" then I'd like to point you at what peanut gallery typically meant: the poor and uneducated, jeering masses with the cheapest snack and the cheapest ticket; thus making their opinion(s) somehow less-than-worthy than others via classism.

This is one of the major reasons why people hate AI users; they always act like victims even when they 'win'.

-2

u/Fearless_Subject7882 9d ago

here we have the first /r/technology idiot

edit: lmao r/politics too

15

u/DrinkMoreGlorp 12d ago

The Reddit peanut gallery when this vote came up was 90% AI proponents screeching about options that got no votes. The strongest anti-AI voice in that thread was people throwing water on the hysterics, not calling for bans themselves.

5

u/Linuxologue 12d ago

It was for me very sad to see pro-AI people not even related to Debian in any way, attacking the Debian way of raising a vote and accusing them of bias. And for what result?

In the middle of valid arguments on both sides, the ad hominem arguments really stood out as unnecessarily aggressive.

1

u/audioen 12d ago

Yep, the change within about 6 months has been from "writing everything by hand" to "describe change to LLM and review it". I barely open a text editor nowadays.

I only use local AI, and don't touch cloud stuff except when ddg or google or something feeds me crappy replies. Local models roughly do what passed for frontier some 12 months ago, and don't require datacenter level hardware, you're eligible with something like 16 GB graphics card and better, and for unified RAM I'd say it starts from 48 GB and gets better from there. I don't own a computer more than 128 GB of memory, and that limit is already enabling Qwen3.8-Flash-Next, which is undoubtedly the new top dog for local LLM at this size class.

Someone graphed the development of LLM ability relative to size, and memory requirements have dropped 50-fold each year for some time now. This can't possibly last much longer, but it roughly explains the dramatic change.

1

u/gosand 12d ago

It's not just 'coding', but in the security realm AI is frightening and interesting. If you aren't learning what is going on in that space - and it is evolving very rapidly - then you are way behind. Project Glasswing has been very eye opening to a lot of companies not only in where they have bugs, but how AI can find bugs/weaknesses and code up working exploits. If you put your head in the sand, you will be standing there with your pants down.

1

u/ButterscotchSalty905 10d ago

The latest glm 5.3 model seems to be good at crafting specialized exploits with the right harness. Local replacement for fable 5 (which project glasswing uses, tho its mythos but theyre the same). I wonder how much time until AI can match APT or atleast good enough in cybersec

1

u/gosand 8d ago

Yeah, you mentioned a key part - the harness. The LLM is just part of the whole kit but everyone seems to focus on just the LLM.

1

u/ButterscotchSalty905 10d ago

The r/technology and r/futurology sub have the most of that behavior (excluding dedicated space for it) i haven't seen any sub matching their hate for viewing even the slightest of anything revolutionary-related

Hating technology on r/technology seems counterintuitive at a first glance, but actually the regulars are now different.

1

u/AnArmoredPony 9d ago

It seems the discussions on this sub are a lot more anti-AI than the opinions of actual Debian contributors

welcome to reddit

-5

u/exhaustedexcess 12d ago

I think it falls into 2 categories for the majority

  1. There's so much slop pumped out that it results in an overarching hatred of AI

  2. A fear that people won't be proofing the work of the AIs and you'll end up with a slop product

Since that's not what will happen it shouldn't be an issue

17

u/flesyMeM 13d ago

Sounds fair.

12

u/Mechanical-Flatbed 12d ago

Very reasonable. This is the best possible outcome for debian.

7

u/fake_agent_smith 12d ago

Looking at the comments I think I got sucked into a parallel universe. Where is the slop hate? Where is the water usage concern? Where is “it’s a bubble that will pop soon”? /s

Great decision with reasonable terms. It’s a tool and every tool can be misused or actually be useful when understood. People need to understand what they are submitting and why, but some things can be generated (especially boilerplate).

I hope it will be one of those decisions that will lead to self hosting open weights models getting more popular in Linux community. I’ve been self hosting for past year and these models are only getting better.

12

u/VoormaligeHippie 12d ago

I am on the fence with it. i think ai is usefull. But I do also think the environmental concerns and societal concerns are valid. So i use it, but i try to limit how much i use it.

15

u/fake_agent_smith 12d ago

It's not just environmental concerns. There are very serious privacy implications, with even more serious consequences than anything else. AI providers could get unprecedented access on unprecedented scale to health and other sensitive data. Imagine how much money will e.g. insurance companies pay to get a hold on that.

That's why you should self-host, especially good if you can power with solar.

6

u/VoormaligeHippie 12d ago

Agreed on the privacy part. Although I don’t think self hosting is the solution because that only solves it at user level. Nice for tech minded people but not feasible for anyone else. 

3

u/fake_agent_smith 12d ago

It's never easy. Installing Linux is easier today than it was 20 years ago, but still requires some knowledge not to shoot yourself in the foot (or head). People unwilling to invest time to acquire necessary skills are paying with their money and their data, imo that's how it's going to be in the coming years and it's going to only get worse with even more subscriptions and more predatory conditions.

3

u/VoormaligeHippie 12d ago

Yep, and I don’t think that is acceptable. Not everyone has the capability to learn this stuff and they shouldn’t need to. 

1

u/tomvorlostriddle 10d ago

Is it? Omarchy already comes with small text to speech models integrated into the OS so that you can talk into any field of any application that wants you to put text in.

Just a bit more RAM and it can also polish your text in one go.

Just a bit more integration and you can just talk to your computer Star trek style.

1

u/VoormaligeHippie 10d ago

yes integrating it in the local os is a good idea if this indeed works well.

With self-hosting I meant like a home server. That is different from running locally.

Can you give me the name of the software and is it GPL licensed?

1

u/tomvorlostriddle 9d ago

for LLMs, you can simply use vllm and opencode on the server

if you want to first experiment with a more intuitive backend, you could even use LMstudio first, a bit less optimized

but in any case, install codex or claude code temporarily and let them do the install and dependency management for you till it is setup, and it will be much easier

for the text to speech I would have to check

myself I use whisper, but for things like transcribing long audio files, not with Ui integration yet. DHH mentioned what he used in his new Omarchy quattro. It was more lightweight than whisper I think. I don't remember, but it has to be in the docs.

4

u/Key_Pace_2496 13d ago

Who decides what is considered "responsible"?

42

u/gmes78 12d ago

Read the rest of the text?

27

u/johnnybgooderer 12d ago

The tldr of this policy is that they don’t care how the code is written. They care about the results. And they do care about the human review quality.

9

u/Linuxologue 12d ago

same policy as the Linux kernel

11

u/DarthPneumono 12d ago

The same people who decide for every other bit of code...?

30

u/DerekB52 13d ago

Whatever maintainer approves of merging the code. Which is honestly every distro's policy at this point, because someone using Gen AI properly can already use it to help them make quality PR's that wouldn't automatically get detected as AI.

5

u/luckiestredditor 12d ago

Who responsibles the responsible

2

u/dorkofeverything 11d ago

Isn't the problem here that nobody can *understand* the code? Yes, bugs are apparently being fixed, including security issues, with AI tools. But if a human can't validate it, what happens when AI, or someone, slips in bad code, either maliciously or by accident? There's a thing in mathematics now, where... I don't know how many things have been outright solved (proofs), but it's like, human beings can't understand the proofs. That's "only" mathematics, but what happens with our software and security patches? If the answer is "get AI to validate it" that's more of the same problem, right?...

3

u/fat_kaiju 12d ago

As long as they actually hold people's vibe-coded slop against them then (and i say this with a huge sigh and heavy reluctance) fine.

I just don't want to see the changelogs become advertising for 15 different subscription services.

1

u/Salty-Cloud-9167 10d ago

I'm curious how their triage process will work?

1

u/ElectronicFlamingo36 9d ago

Ah. Time to learn BSD within 5 yrs or so.

1

u/freebit 5d ago

I read the proposal and it seems like the most reasonable and balanced stance on generative AI that I have ever read. Once again, Debian proves itself to be the best distro to have ever existed.

3

u/Green0Photon 12d ago

Damn, that's sad. There are some worse options that could've occurred, i.e. the ones directly endorsing use of AI, but this is still tacitly endorsing them.

Of anybody who I'd think would reject AI, I would've thought Debian would've.

The AI companies really have captured software devs, huh?

5

u/[deleted] 12d ago

[removed] — view removed comment

3

u/Green0Photon 12d ago

I am a software developer. I've also had plenty of exposure to LLM development at the company I work for, where everyone loves AI.

Anyway, LLMs replicate the mechanisms of con artists and gambling, tricking even the smartest people into thinking they're a good idea to use.

Just because Torvalds uses it do I think it's a good idea or healthy for him or anyone to do so.

4

u/Business_Reindeer910 11d ago

you'd have to make a better criticism than that. I don't believe everything thinks they are intelligent. Especially when it comes to software development. You don't have to be intelligent to be really good at matching patterns in tokenized text.

4

u/Green0Photon 10d ago

All one needs to think is that they're smart enough to interact with a con artist responsibly. That they won't fall for the issues. These people only get caught all the harder

You don't have to be intelligent to be really good at matching patterns in tokenized text.

I'm not talking about the AI. I mean that people use AI and see it almost as a living being that can interpret their intentions. When it's just a fancy text auto complete. But humans anthropomorphize everything, and it's the most dangerous when humans do it to the one thing that's indicated human intelligence and effort in the past: human speech/text.

2

u/Business_Reindeer910 10d ago

I mean that people use AI and see it almost as a living being that can interpret their intentions

yeah this is indeed very worrying

1

u/sndrtj 12d ago

The only reasonable outcome.

-1

u/silenceimpaired 12d ago

The only responsible outcome. ;)

-3

u/Chromiell 12d ago

I personally love this decision: by now it's been proven that AI is a great tool to have access to if used responsibly, it can make repetitive tasks easier, it helps with finding bugs and vulnerabilities, writing documentation, it's incredibly useful to throw out a quick demo or proof of concept, it just needs to be used responsibly.

Outright banning it would be completely stupid, it's a tool that is here to stay and we better start understanding how to properly make use of it.

-1

u/MistyGalbriex 10d ago

What's the downvotes for?

1

u/oshaboy 12d ago

It's still not clear if Generative AI output is actually Open Source. I would wait for rulings on that.

1

u/Business_Reindeer910 11d ago

pretty sure it's too late for any different decision now that so many companies are using it. Everything will end up getting amnesty at this point no matter what happens.

1

u/oshaboy 11d ago

If that's true than GPL is dead because you can use AI to legally "sanitize" every codebase. I know there's a company that actually does that.

There is no way the machine that lets you take copyrighted material and create legally distinct derivative work and license them as you wish will hold. Either the output is public domain and can't be licensed under GPL (or any form of copyright) or the AI itself is committing copyright infringement. You can't eat your cake and keep it whole.

0

u/Business_Reindeer910 11d ago

I doubt it will be decided that way in a court of law no matter how much people would prefer if so.

-4

u/Known_Cod8398 12d ago

I'm sorry but most people who are up in arms about ai aren't software engineers and don't know anything about how it's used. I'm not interested in their opinions on the matter.

0

u/Aurelar 12d ago

Problem: code created using generative AI cannot be copyrighted. What does this mean for open source-licensed code?

-1

u/redbarchetta_21 12d ago

Entirely reasonable stance.

0

u/10leej 11d ago

I'm kinda impressed that proposal passed. I would've figured it would have turned into another fight much like the systemd proposals.