policy-regulation
Ban on LLM-assisted code goes to a Debian vote
Promtime
policy-regulationDebian has put eight competing proposals on the use of LLM-assisted contributions to a project-wide vote, the strictest of which would bar such work from the distribution entirely. The general resolution, reported by The New Stack, pits an outright prohibition attributed to Matthias Geiger against seven alternative texts.
At a glance
- The strictest text would bar direct contributions written with the use or assistance of large language models, covering source packages, packaging, native software such as the lintian package checker, documentation and translations.
- Proposal A would have to clear a 3:1 majority to pass, while the seven alternatives, from conditional acceptance to a climate-based objection, each need only a simple majority.
- Upstream projects fall outside any ban, and patches or security fixes originating upstream could still land, so maintainers would still package third-party tools they were forbidden to use themselves.
A ban would turn code provenance into a membership rule rather than a review criterion, and the eight-way ballot suggests the disagreement inside Debian is about disclosure mechanics more than principle. The strain lands on maintainers: the same people who would keep packaging AI-generated upstream software would be judged on whether their own work carries a model's fingerprints, a line that looks hard to police as tooling improves.
The ban would cover packaging, lintian, documentation and translations
If approved, the prohibition would apply to Debian source packages and other software developed by the project, official Debian web resources, direct code contributions defined as packaging, native Debian software such as the lintian package checker, and documentation and translations written by contributors.
It would not reach upstream software engineering projects that use generative AI, and it would not block patches or security fixes coming from upstream sources. Debian developers could still find themselves packaging third-party AI-coded tools, while being barred from using those tools for new direct project work.
The text attributed to Matthias Geiger grounds the position in Debian's reputation for stability and states that the community sees widespread LLM usage as an expression of the move fast and break things attitude common elsewhere in the industry. The proposal says that approach is inappropriate for Debian contributors.
Seven alternatives run from conditional acceptance to a climate objection
Other proposals would allow AI-assisted contributions with conditions, reject LLMs as far as practical while updating the code of conduct, accept AI work on Debian-specific code, set responsible-use guidelines, or pledge that Debian is created by humans; one objects on climate grounds under the title "avoid the use of LLM: climate destruction is a deal breaker".
Joe Phillips, author of the Hybrid Workforce Standard, told The New Stack that Debian already agrees provenance must be declared and that the eight-way vote is an argument about how big the sticker on code origins should be. He points to the proposal's community section:
contributors who lean on a model never learn packaging, so they can never replace the maintainer who burns out
Phillips calls that deskilling the one harm that compounds, and the same risk he requires organizations to name and measure in his consultancy work. His answer is apprenticeship rather than prohibition: new contributors in shadow mode, reviewed like juniors, earning authority.
Beals and Brown want verification in the pipeline instead of a prohibition
Justin Beals of compliance platform Strike Graph told The New Stack the ban is the wrong fix for the actual problem: nobody has built a reliable way to verify what an AI agent produced before it lands in a codebase this many systems depend on. Debian is said to have replaced Windows on the International Space Station in 2013.
He argues a blanket ban removes one trigger while leaving the trust model untouched, and that projects will come out ahead by building verification into the contribution pipeline: provenance tracking, review depth tied to actual risk, and evidence a human validated what shipped.
Matt Brown, principal AI architect at Endor Labs, told The New Stack a blanket ban risks confusing the tool with the quality of the work and would make AI use harder to disclose, since nothing stops a contributor retyping generated code. For him the test is whether the contributor understands, verifies and stands behind the code.
The 3:1 threshold on Proposal A
Voting closes on Friday, 2026-08-28 at 23:59:59 UTC. Proposal A, the outright ban routed through the social contract, has to clear a 3:1 majority, while proposals B through H need only a simple majority. Until the result is declared, every option remains a proposal, and no implementation timetable has been published for whichever text wins.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
