The without disclosure part tells everything you need to know here. If it’s such a benign and maybe even beneficial thing to do then why are you hiding it? What possible reason could you have not to label that? In an open source Community shouldn’t everything like that be known?
I wonder what’s the reason to make it optional? I think I’ve seen this approach with other projects as well. Isn’t transparency and accountability a good thing? Also, this kind of information helps immensely when reading pull requests or silly bug reports. And Debian acknowledge there might be licensing issues. So it might become some sort of liability to them once it taints everything and we can’t even tell?! So why? What’s the upside? Adorn oneself with borrowed plumes and not being forced to disclose the fact? Or too much bookkeeping?
I think it’s just the simple fact that there’s no way to enforce it
so the solution then is to just give up??
sorry but that’s obviously nonsense, you can have unenforceable rules, god isn’t going to smite you for doing so.
There are ways to enforce it. Yeah, you won’t be able to make everyone follow the rule, but it’s the same with any law and any public policy and they’re still valuable. You don’t make campaigns against DUI because you expect everyone to stop doing it, as that’s a nirvana fallacy, you make them because you expect them to reduce DUI.
Because the idea is to judge the code by its quality, not by who or what wrote it.
I think that’s a commendable effort. Usually I do it the same way. Just feels massively unfair to me towards human contributors. I’ve seen the AI pull requests and bugreports come in. And it’s very time consuming to deal with them. They’re long, convoluted, touch a lot of code… There’s frequently a good amount of “hallucinations” in them, because they’re sent in autonomously or by people who don’t know what they’re doing. There might be dozens of them in quick succession as with the larger projects. They eat up time and effort which is now missing to deal with human contributions or wishes. My own opinion is: Transparency would help a lot to prioritize stuff. I mean AI isn’t sentient, and as long as that holds true, I’d rather treat people with respect and the amount of attention they deserve… (In contrast to a level playing field between human and machine… Because the machines will easily beat us by sheer volume.)
True, but I think the kind of people who send those monster PRs either already have AIs cosign it or they aren’t reading the policy anyway. There have also been a number of studies that show LLMs usually ignore this kind of instruction.
Hmmh. Sure. People also deliberately instruct their agents not to reveal the fact. I can empathize with that, because there’s all these people out there yelling at you, and launching shit storms.
I believe the uptake in “co-authored by …” is due to some companies making it the default setting in their frameworks. It’s to some degree Microsoft being nice to us, not necessarily benevolence of the people sending in those PRs. Doesn’t really matter to me though. It’s enough to make me happy if that’s attached to some commit or PR. I don’t care how it got there, as long as it fits the purpose.
Edit: And thanks for your comment. I don’t think I agree. Nonetheless this might be the answer to my question.
There are so many levels of LLM involvement and once you make this distinction you actually have to devote some of your limited resources to define and enforce it. So I think it might not be strictly beneficial, but possibly also have downsides.
Where would you draw the line at which point it counts as LLM involvement? Having one run as some sort of spell/syntax checker? Doing some research (and being influenced by it) before hand coding something? Having it create a working prototype and then reimplementing it by hand? If you use code from somewhere else to solve a problem and ai use has not been disclosed for this code, do you automatically have to assume LLM usage was involved or is there plausible deniability?
I think in the end you’d have to use too many resources check it and debate where the line is drawn, when the real question is how you retain human knowledge and engagement within your community.
Just disclose how you used it.
“Just” like with GDPR, “just” follow the rules for personal data management. In reality, compliance stuff like that is expensive to implement.
So if you are going to require it, don’t pretend it is without cost. Which is exactly what you seem to be doing.
We saw this play out with GMO foods:
If it’s such a benign and maybe even beneficial thing to do then why are you hiding it? What possible reason could you have not to label that?
later:
It’s specifically labelled, therefore it must be bad right? If we didn’t need to worry about it, it wouldn’t be labelled.
In the us anyway the food is labeled as bio-engineered, and everyone still buys it
Conversely… if it’s so benign, why should it have a label?
Not really worth discussing - it’s not benign, and it can be made purposefully not benign by a third party without notification or knowledge. A third party who has already demonstrated a penchant for world domination, both technologically and physically.
I should hope that open source developers are exclusively using open source models that are trained on open source projects.
I mean, I would think, at least. It seems to me that most of the people in charge of big projects are usually FOSS purists.
That’s part of the reason why AI scrapers are breaking the small web. FOSS purists really have no significant defense against it aside from Anubis.
Real DoS protection comes from capacity, which costs serious dollars, especially in this day and age where botfarms can be hired by the hour for rather cheap and record-breaking attacks seem to happen like monthly.
The alternative is using a CDN, but there are none that align with FOSS ideals. And for CDNs to be really effective, you need them to break open TLS and handle the decrypted traffic, which raises privacy concerns on top.
But anyways…most license agreements would make it a requirement that if you’re using an open-source model, that it be properly attributed, right?
I should hope that open source developers are exclusively using open source models that are trained on open source projects.
Most developers who use these tools (even FLOSS developers) appear to be using the corporate owned models that were definitely trained on both proprietary source code and code that is incompatible with the GPL license. Some EU courts have also already judged that LLM code cannot be copyrighted, which also means it cannot be licensed as GPL.
Currently, all code generated with an LLM has a 3 to 10% chance of unknowingly plagiarizing the copyrighted code it was trained on, and any FLOSS project that uses it is making a huge gamble that their codebase won’t be scanned by corporations in the future looking for violations to sue about, shut down rival FLOSS projects, etc.
“AI scrapers break the web, to use this page you’ll need JavaScript enabled.”
The ironic…
@ProdigalFrog
> “Pretending to have a “neutral stance” when faced with fascism is not neutrality, it’s active collaboration.”Bars. I’m sure it wasn’t an easy decision, I hope Antoine gets to keep his peace undisturbed.
Fascism is when people can use AI.
Not on its own, but an unfortunate goal of fascism is ruining education so that people have opinions like yours
So you agree with me, that AI is not fascist, but at the same time you say that one of goals of fascism is for people to think that AI is not fascist.
Am I reading it right?
You are, in fact, not reading that right.
Let me spell it for you because you apparently fell victim to the previously mentioned attack on education: AI is a tool. Like any tool it is not inherently evil, but the fascists love to take potentially useful tools and turn them around to cause as much suffering as possible. In this case, AI (more specifically LLMs) is used to make people reliant on it by getting them addicted to outsourcing all their problem solving skills while also reducing the value of art and artists of all types so they can take the money that artists would have made and also control ‘art’ (can’t have any pesky artists drawing pictures of people beating the nazis up) all the while sucking up every single data point about you.
If that’s all too complicated for you to understand, I guess you could over simplify it as “fascism is when AI”
Does that mean internet is fascist? Search engines? Calculators? Writing?
All of those things outsource your congnitive skills.
Almost nobody is saying that AI art generation is a complete subsitute for conventional art.
Even if all of that were true, it wouldn’t make AI fascist, but totalitarian.
Acting as if using an LLM is similar to using a calculator or search engine is a ridiculous comparison and further proves it’s not worth engaging with you further
Respect to Antoine. Having principles that are worth a damn is a rare trait amongst developers these days.

The world needs more people that act on principles and take a stance.
Weird that he didn’t care when Linus Torvalds adopted basically the same policy to the kernel that serves as the foundation of the main Debian distribution. I have an inkling that there is more going on at Debian, not LLM use alone.
didn’t he? have you checked?
the main thing is that it’s an upstream problem. the linux kernel is used in nuclear missiles. if you want to stay on that kernel you have to take what you are given. in your own organisation you can at least try to change things.
the linux kernel is used in nuclear missiles
source:
Idk anything about this…but here is my Google results
Don’t think golden dome is actually implemented, though just some trump delusion…but apparently this Redhawk Linux is used in…
This is an educated guess but I think the entire US nuclear arsenal is so old that it predates Linux entirely.
Nuclear missiles probably run vxworks or another rtos, not linux
FOSS nukes when?
He didn’t leave the Linux-based OS for Linus Torvalds himself stating a similar policy for the Linux kernel before Debian did.
Debian has a history of maintaining ancient kernels. But it’s hard to believe that he assumed Debian to just fork Linux…If he resigned only now, he didn’t resign before. What is there to check? That is common sense. Linus allowed LLM use and he was fine with Debian building on it. After all, all LLM use is literal fascism in his eyes.
Good, someone with morals
If they had those, they wouldn’t be wasting electricity by being on the Internet. Causing global warming with their use of technology. They’d be sitting in a cave, meditating to reduce the harm they cause to the environment.
Yet you use a computer, curious! I am very intelligent.
You, too? Nice! That makes two intelligent people.
Want to do something really intelligent together? Like try to enforce a ban on AI even though it’s use is undetectable and fundamentally it’s just math?
you not being able to detect LLM use is not our problem
🤣
You not being able to detect the eye color of someone over the phone is not anyone else’s problem.
That’s a false equivalence. And besides they polute on massivelly different scales
It’s not a false equivalence. You can’t applaud someone ruining the environment to condemn someone ruining the environment. It’s ludicrous.
It’s also not inherently massively different scales. For all you know they posted from a super computer connected to a coal generator, to complain about AI being operated on a Raspberry Pi powered by solar.
Then you clearly have no idea what a false equivalence is
That’s a false equivalence.
Personally i find debian change of policies to include proprietary firmwares by default worst than this
Whoa, that is very unlike Debian.
The point isn’t so much the quality of the code itself.
The point is that AI is an inefficient power-wasting piece of trash, and the data centres that power it have significant negative impacts on people and the environment, all for the sake of devs being lazy idiots. And you’d have to be an idiot to let AI take away your skills.
The point is also that this is the pre-enshittification version of AI, and any person or system foolish enough to become dependent on it will get exploited to the best of AI companies’ abilities.
pre-enshittification?
Then what the hell are the models Windows is relying on if this is the GOOD stuff?
the opposite of “enshittified” isn’t “good.” some stuff sucks for fresh, new reasons before it enshittifies and turns to full on exploitative rent-seeking.
for example, anthropic quietly pulled claude code from their pro subscriptions and made it a separate subscription. that’s enshittification. and stupid AI bros are gonna fall for it every time.
When did Anthropic make Claude Code a separate subscription? I ask because it is still listed as part of the Pro subscription tier on their website. And because I haven’t seen the shit-storm that would no doubt ensue if they did that
Oh so it just goes from bad to worse? I see then
Usually in the context of profit milking by shareholders influencing that decline.
If only there were some community of people who valued using free and open source software so we had options that were not dependent on the whims of companies. Then we could have software that we could depend on that isn’t dependent on the whims of corporations.
Throwing out AI because there are AI companies who causing harm is like giving up on Operating Systems because of the plethora of bad acts made by Microsoft.
I agree that everyone should avoid using OpenAI, Anthropic or any of the other companies which were created to spend trillions of dollars buying up all computer hardware on the planet while building fossil fueled datacenters.
That isn’t the same as thinking that the actual machine learning technology itself is somehow inherently bad. There are many open weight models and FOSS projects that lets people use AI without contributing to the capitalist orgy that’s causing all of the secondary harms.
People conflating AI technology and AI companies are failing to diagnose the issue that we’re facing.
Open weight != open source.
You can can inspect open source software. You can compile the source into binary. You cannot inspect open binary. Well, you can, but it’s difficult. Can anyone ever inspect the fucking weights in a useful way? They are just bias numbers.
The point isn’t so much the speed and comfort of the commute itself.
The point is that a car is an inefficient power-wasting piece of trash, and the oil rigs that power it have significant negative impacts on people and the environment, all for the sake of commuters being lazy idiots. And you’d have to be an idiot to let a car take away your mobility.
This but unironically
Well what would the disclosure requirement improve? It’s unenforceable and it just gets in the way of evaluating the code based on quality. Every code should have high standards. Bad llm code is just as bad as bad human code.
If a project allows llm contributions then disclosing it will only make people wary of the wrong things. Putting a badge on it is not helpful anymore if it’s allowed. I have seen good llm code and bad human code.
The Free Software Foundation of Europe recently published an article detailing why it’s legally quite important for developers to disclose and carefully catalog which code was created by LLMs.
https://fsfe.org/news/2026/news-20260825-01.html
Recommendations for AI usage in Free Software contributions
With these issues in mind, the recently published Recommendations When Using LLM-Backed Generative AI Systems for FOSS Contributions by the SFC outlines some of the legal difficulties for copyright and licensing that generative systems have created for software developers who wish to write, maintain, or contribute to Free Software projects.
Notably for the purposes of this article, the SFC recommends the full recording and disclosure of how and when an AI tool was used to assist in the creation of a contribution. As stated by the SFC:
“FOSS project leaders cannot make good decisions about LLM-gen-AI policy if they cannot survey which contributions were assisted, and how much they are assisted. Part of the contribution process should (at least) include a disclosure of what LLM-gen-AI system was used, its version (as these system change over time), and a brief description of how the system assisted the contributor. This information should be included in a machine-readable format in commit logs."
Indeed, such disclosure can be an important foundational step to allow for the accurate assessment of the copyrightability of code that has been assisted or generated by AI tools, in order to assess their licensability into Free Software. Open and clear disclosure is a helpful step for the Free Software community to maintain a healthy licensing ecosystem, which is currently threatened by the legal uncertainties that come with the advent of generative AI.
Additionally, it is worthwhile for developers to document in some capacity the extent of human work that they have done in their software projects, whether it be the writing of code, the selection and arrangement of components within the project, or the extent of human modification of machine generated content.
IANAL but from my naive perspective it might make more sense to not disclose this because no one can prove that something was written by AI if no one discloses it. That means for me that any claims that a certain part cannot be copyrighted are hard or even impossible to make.
Who?
So Open-Source and FOSS projects collectively decided that they want to jump on half-sunken ship in the middle of the ocean?
Amazing.
Debian, destroying Linux since 2015.
Elaborate? I don’t want to vote just yet, maybe it’s a take I could agree with (what did they start doing 2015?)
The first debian version with systemd was released that year.
fascist-backed technology to be known.
And you’ve lost me already
Word choice or disagreement with the assertion as a whole?
Cars are fascist-backed technology. So are computers. Highlighting such a fact is irrelevant.
Cars are fascist-backed technology.
Ford cars are certainly fascist-backed. Volkswagons, too. Idk if I’m going to stick the label on the Olinia or the Renault.
So are computers.
The Chilean Fascist Augusto Pinochet famously shot all of his country’s computers for being Communist.
Highlighting such a fact is irrelevant.
Weird that you’d bring it up. Weirder that you’d get so many of your facts wrong.
You’re pointing out brands. Brands can be fascist.
The OP is pointing out technology. Technology cannot be fascist.
It’s not, they have different potential consequences
Everything has different potential outcomes…
What does that even mean?
Exactly. It’s all nonsense. But we need to single out this nonsense in particular and hate it. Because it has different potential outcomes…
It’s not allnnonsense. LLMs are being used to “solve” small problems but pollute way more than normal datacenters, way more than you using your personal computer etc. You seem heavilly invested in denying any bad thing from LLMs …
Fascism is when AI.
How is AI fascist?
Is it ultranationalist? Rejecting democracy? Anticommunist or antiliberal? Third position in economics? Anti egalitarian? Racist? Traditianolist socially?
I could maybe see an argument for it being anti egalitarian, but besides that, LLMs have none of those traits.
You don’t understand… ‘fascism’ today means something along the lines of ‘I don’t like it’, like ‘gay’ in the 90s…















