Debian voted AI policy
The Debian project recently voted on 8 different AI policy options. The result is to permit generative-AI-assisted contributions, rather than impose a ban or special mandatory controls. The winning policy—“Responsible Use of Generative AI”—puts full responsibility for quality, security, licensing, and suitability on the human contributor submitting the work.
What passed
The General Resolution’s winning text says Debian neither endorses nor prohibits generative AI in development, package maintenance, documentation, or other Debian-published material.
Its core principle is tool-neutral: a contribution must meet Debian’s existing standards regardless of whether AI helped create it. A contributor is expected to understand, review, test, and revise AI-assisted output as necessary; blindly uploading generated output is explicitly characterized as inconsistent with Debian practice.
It also says contributors should:
- Consider copyright, provenance, and license risks before submitting material.
- Keep confidential material out of third-party AI services—especially embargoed security information, credentials, private discussions, personal data, and other non-public Debian information.
- Discuss and gain appropriate consensus before large-scale automated actions, such as mass bug filing, patch submission, or broad code changes.
- Disclose AI use where appropriate, but disclosure is encouraged rather than mandatory.
What did not pass
The ballot included eight policy alternatives ranging from outright prohibition to permissive use with varying safeguards.
| Option |
Basic approach |
Result |
| A |
Add a Social Contract ban on direct LLM-assisted contributions |
Failed its required 3:1 majority |
| B |
Allow AI with legal, accountability, disclosure, bulk-change, and privacy conditions |
Passed simple-majority threshold, but lost to the winner in head-to-head ranking |
| C |
Ask contributors to avoid LLMs; prohibit AI-assisted messages to people and require disclosure |
Failed majority |
| D |
Permit AI for Debian-specific work with accountability, marking, and confidentiality rules |
Passed threshold, but not selected |
| E |
Responsible use; no special prohibition, mandatory disclosure, or separate AI regime |
Winner |
| F |
Cautious policy encouraging avoidance where practical |
Passed threshold, but not selected |
| G |
Permit assistive use but ban generative output as direct Debian contributions |
Passed threshold, but not selected |
| H |
Encourage avoidance chiefly on climate grounds |
Passed threshold, but not selected |
The strict Social Contract ban received 144 votes over “None of the above,” versus 257 against it, so it was far from the needed 3:1 ratio. The winning option received 281 votes over “None of the above,” versus 126 against.
Why option E won
Debian uses a ranked Condorcet-style election system: rather than simply choosing the option with the most first preferences, it compares proposals pairwise. Option E was the sole member of the Schwartz set and beat every competing option in the relevant head-to-head comparisons, making it the unambiguous winner under Debian’s procedure.
Notably, E beat:
- The “allow AI with conditions” option B, 203–148.
- The cautious/avoid-where-practical option F, 210–130.
- The “humans create Debian” direct-output prohibition G, 251–139.
- The climate-focused avoidance option H, 244–154.
- “None of the above,” 281–126.
Practical meaning
For a Debian maintainer or contributor, this is not a blanket approval of generated patches. It means AI assistance is allowed, but normal Debian expectations remain fully in force:
- You own the submission and must be able to explain and defend it.
- You must verify it technically and legally, including licensing and provenance.
- You must not leak private or security-sensitive project information to outside AI services.
- Automated or high-volume AI-derived changes still require normal project discussion and human oversight.
- Saying an AI helped is good etiquette, but the adopted resolution does not make it compulsory.
The resolution was discussed from July 23 through August 13, 2026, with voting held August 15–28. Of 1,045 eligible Debian Developers, 425 ballots were tallied.