Debian Adopts "Responsible Use of Generative AI" — the Ban Option Missed Its Supermajority
Debian's General Resolution on LLM usage has concluded, with "Responsible Use of Generative AI" winning out of eight options. It neither endorses nor prohibits the tools, and leaves review and legal accountability with the contributor.
The Debian Project’s General Resolution “LLM usage in Debian” has concluded, and out of eight options Choice 5, “Responsible Use of Generative AI,” won1. Voting ran from 00:00:00 UTC on August 15, 2026 to 23:59:59 UTC on August 28, 2026, following a discussion period from July 23 to August 13 that was extended1.
The heart of the adopted text sits in a single sentence: “Debian neither endorses nor prohibits the use of generative AI tools”1. A condition comes attached. Regardless of how and with which tools a contribution was produced, the project expects it to satisfy the same standards of quality, correctness, maintainability, and legal compliance1.
Not “You May Use It” but “The Responsibility Does Not Transfer”
What the adopted text returns to repeatedly is not whether the tools are good, but where responsibility sits.
Using a generative AI tool does not diminish the contributor’s responsibility for the work they submit, and contributors are expected to understand, review, test, and where appropriate modify AI-assisted output before incorporating it into Debian1. Blindly accepting or uploading AI-generated material without appropriate human review, the text says, is inconsistent with Debian’s established development practices1.
On disclosure, the project encourages contributors to say whether a contribution was AI-assisted, but does not require it1. Given how hard such a requirement would be to verify, that line looks like a practical place to draw it.
The closing paragraph makes the same point: generative AI is neither exempt from nor subject to special rules beyond the standards already expected of Debian contributors, and responsibility for every contribution rests with the contributor who submits it1. This is less a new rule than a confirmation that the existing rules apply to AI equally.
It Explicitly Declines to Settle the Copyright Question
The second striking feature is how the text handles the legal questions.
It acknowledges that the legal status of material produced by generative AI systems remains under discussion in many jurisdictions, and states that the resolution does not seek to resolve those unsettled legal questions1. It also declines to take a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works1.
What goes in its place is the judgment of individual contributors. They are expected to consider provenance and licensing implications, and to avoid introducing content whose legal status they cannot reasonably justify1. Existing Debian policies on licensing, copyright, and software freedom continue to apply irrespective of the tools used1.
The copyright status of AI-generated work is still unsettled across jurisdictions. Rather than fixing a project-wide view ahead of that, Debian chose to leave the call to contributors and absorb it through rules that already exist.
Guardrails on Confidential Data and Large-Scale Automation
Two constraints in the text bite immediately in day-to-day operations.
The first concerns data leaving the project. Confidential information, private communications, security-sensitive information such as embargoed information about security bugs that is not yet public, cryptographic keys, credentials, and other non-public material are not to be disclosed to third-party AI services unless that disclosure has been explicitly authorized and is consistent with Debian’s security and privacy requirements1.
The second concerns scale. Actions with broad project impact — mass bug filing or patch submission, large-scale code modifications, other automated changes affecting many packages or contributors — should go through prior discussion and consensus in the appropriate project channels, and any such automated process should be overseen by a human who remains accountable for its behavior and output1. Once agents can produce pull requests at machine speed, the question of who absorbs the review load cannot be avoided. Debian draws a line on the same problem that Copilot code review reached from the other side when it began covering bot-authored PRs.
The Ban Option Could Not Clear 3:1
There were eight options on the ballot, ranging from Choice 1, “Ban LLM contributions from Debian via Social Contract,” to Choice 8, “Avoid the use of LLM: climate destruction is a deal breaker”1. All eight reached quorum (48.4896896257338, against 1045 voting developers)1.
Choice 1 alone required a 3:1 supermajority — the other proposals needed a simple majority — and at a ratio of 0.560 (144/257) it was dropped1. Choice 3, “Reject LLMs as far as practical, update Code of Conduct,” also failed to pass majority and was dropped (0.765, 176/230)1.
The winning Choice 5 defeated every remaining option. Against Option 9, “None of the above,” it stood at 281 to 126, a majority ratio of 2.2301. Because Debian uses the Condorcet method, these are not simple for-and-against headcounts but pairwise tallies between options1. Choice 5 was proposed by Marc Haber; the ban option, Choice 1, was proposed by Matthias Geiger1.
The concerns raised by the defeated ban option are worth reading too. It listed four — copyright, quality, community, and ethics — and on copyright argued that while the legal status of LLM output is very unclear, Debian Policy and the DFSG require absolute clarity on licensing and copyright1. Under ethics, it described large-scale scraping for training data as having had a major negative impact on Debian’s public web resources, leaving parts of the infrastructure unreachable and forcing JS-based checks to be enabled1. The ban did not pass, but those concerns did not go away with it.
Read as a Template for an Internal Policy
For anyone drafting an internal policy on AI-generated code, Debian’s resolution is a fairly usable template. Instead of a binary between banned and allowed, it draws its lines at three points: where responsibility sits, where the boundary for confidential data runs, and what large-scale automation requires by way of prior agreement.
Precedents in this area are accumulating. Another proposal in the same vote (Choice 7) explicitly noted that it was inspired by GCC’s AI Policy and rust-lang’s LLM Usage Policy1. When more than a third of the web pages datable to after ChatGPT’s release show traces of AI authorship, a design that tries to detect whether AI material is present at the door tends to work less well than one that assumes it is and specifies responsibility and verification instead. Debian picked the latter.
The adopted text says of itself that it describes the project’s position at the time it is adopted, and that the position may evolve without resorting to future general resolutions1. The conclusion is placed as a starting point that can move once it has been lived with, not as a settled endpoint.
Sources
- General Resolution: LLM usage in Debian - Debian Project official vote page (voting period August 15-28, 2026)
- Debian Votes To Allow “Responsible Use Of Generative AI” - Phoronix (August 28, 2026)
Was this article helpful?
Thank you!
Received. Thank you!