Debian Votes for Responsible Use of Generative AI, and Rejects the Ban

Debian Votes for Responsible Use of Generative AI, and Rejects the Ban

Debian’s General Resolution on generative AI has resolved. Option 5, “Responsible Use of Generative AI,” won, and the project now has a formal position: AI tools are neither endorsed nor banned, and the human who submits the work remains fully accountable for it.

We covered the ballot while voting was open. The result landed close to where the ballot mechanics suggested it would.

The numbers

Option 5 was the only option in the Schwartz Set under Debian’s Condorcet method, meaning it beat every other choice head to head. The margins were not narrow:

  • 203 to 148 over “Allow AI-Assisted Contributions with conditions”
  • 210 to 130 over the more cautious variant
  • 232 to 115 over “Accept AI contributions for Debian-specific work”
  • 251 to 139 over “Debian is created by humans”

The Social Contract amendment banning LLM-assisted contributions did not reach its required majority. This is the part worth dwelling on, because it is exactly what the asymmetric threshold predicted: that option needed a 3:1 supermajority while every competitor needed a simple majority, and several competitors were close enough in spirit that a developer uneasy about AI could rank one of them highly without abandoning the position.

An outright ban was never impossible. It just needed overwhelming support rather than majority support, and it did not have that.

What the policy actually says

Debian will not treat “AI-generated work” as a separate category with separate rules. The framing is that generative AI is a tool, and tools do not carry responsibility.

Contributions made with AI assistance must meet the same standards for quality, accuracy, maintainability, and legal compliance as any other contribution. Using a model does not dilute the submitter’s responsibility for what they submitted.

Disclosure is encouraged but not required. This makes the winning option meaningfully less restrictive than several of the alternatives, and it is the detail most likely to be argued about later. There will be no AI-assisted tag in changelogs, and no way to query how much of the archive was written with model assistance.

There are hard limits on what goes into third-party services. Contributors must not send confidential information, private communications, security vulnerabilities, cryptographic keys, credentials, or other non-public Debian data to external AI providers without clear permission and compliance with Debian’s security and privacy rules.

That last clause is the one with teeth. It is a concrete, enforceable rule about data handling rather than a statement of principle about authorship.

Why the outcome was not really about code quality

The debate was never mainly about whether models write acceptable patches. It was about review capacity.

Debian runs on volunteer reviewers, and a flood of machine-generated contributions consumes that capacity whether or not the patches are any good. The Linux kernel’s networking maintainers described themselves as completely overwhelmed by precisely this during the 7.3 merge window, and OpenSSH moved to more frequent security releases under the same pressure from AI-assisted vulnerability reports.

The resolution does not solve that. It declines to solve it through prohibition, and instead pushes the burden onto the submitter: if you send it, you own it, and “the model wrote it” is not a defence.

Whether that holds in practice depends entirely on whether maintainers are willing to reject work from contributors who clearly have not read what they submitted. The policy gives them the standing to do so. It does not give them more hours in the day.

Why this matters beyond Debian

Debian is one of the oldest and most influential community-run distributions, with thousands of packages and an enormous downstream ecosystem including Ubuntu. Its governance decisions get cited.

This is now the reference point, in the same way the non-free firmware vote became the reference for that question. A project debating its own AI policy can point at a large, conservative, process-heavy distribution that considered a ban through a formal binding vote and declined to adopt one.

The contrary reading is also available: a project can point out that the ban lost on a supermajority technicality rather than on the merits, and that a simple-majority ballot might have gone differently. Both readings are defensible from the same numbers.

Full details are in Debian’s announcement and on the vote page.

Background reading

Explainers for the concepts behind this story.