Debian permitting use of genAI:
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil Well, with even the Linux kernel accepting the use of LLMs... maybe it's time to start looking towards BSD, maybe even specifically NetBSD as they seem clearest on the case.
Code runs deep and sometimes fast and so does this issue.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
On point 4, asking as someone also wondering about this (not on Debian, but because I'm on a Distro + DE that have been permitting genAI): Given that the underlying kernel has been, hm, polluted, will that be having an impact on your decision about whether to take the time to move distros?
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil went through the same cycle yesterday, but the only system I saw which is hard "no" mentioned was NetBSD which, tbh, looks a pain to use.
After pondering, I think the real issue for me isn't Debian, it's the kernel. Linus and the foundation opening that door means *every* Linux distro is "tainted". I see no issue with a distro allowing it if I can actually move to one that doesn't, but the kernel is the kernel. 🤬
-
On point 4, asking as someone also wondering about this (not on Debian, but because I'm on a Distro + DE that have been permitting genAI): Given that the underlying kernel has been, hm, polluted, will that be having an impact on your decision about whether to take the time to move distros?
@feff Yes, and perhaps I should have been "on this" sooner.
I could do nothing, adopt a watching brief, and pretend that that makes me neutral on the topic.
And doing nothing is definitely superficially attractive, because the doing something meaningful is a huge amount of work.
I'm pretty sure that even our doorbell runs Linux.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil I am not sure if this is worth the effort. In a few years all distros/maintainers will permit using genAI. Perhaps there will be "vinyl" distributions without

-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil 39% of Debian devs voted to discourage or ban LLM use.
It’s almost the same fraction as the fraction of those who voted to avoid dependency on systemd.
And I think it shows that the push to get stuff into Debian is strong again. Exactly because the blast radius is so big.
Existing discussion on the topic with some evaluations:
https://rollenspiel.social/@janneke@todon.nl/117178677006767849 -
@neil @tschenkel that is very tempting unfortunately very tricky given our dependence on complex infrastructure.
I imagine keeping a herd of goats and tending to an olive grove
@mhagdorn @neil @tschenkel Or donkeys
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil thanks Neil for your thoughts.
So Debian in the past has done some possibly questionable decisions like systemd.
I am aware of the environmental harm that AI is doing. On the other hand I can imagine a future where we all run a low resource local AI on better hardware and where there isn't so much money being pumped into these data centers anymore. However nobody knows the future and the sooner these firms go bankrupt, the sooner that there will be some alignment between environmental cost and financial cost.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
-
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
> And that would be responsible use AI, right?
What criteria are you using for this assessment? That would seem to be important here, as to whether your conclusion is really just reinforcing your choice to use genAI because you would find it helpful to do so, or if it is a considered, objective stance.
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil appreciate your thoughtfulness on this, even if I don't necessarily entirely share your values.
My issue with this whole thing comes down to detectability and trust. If I point at a git commit, authored by me, and I pinky swear I didn't use an LLM to write, design, or coach me through any part of it, is that sufficient to meet a project's "no AI" policy?
-
@neil appreciate your thoughtfulness on this, even if I don't necessarily entirely share your values.
My issue with this whole thing comes down to detectability and trust. If I point at a git commit, authored by me, and I pinky swear I didn't use an LLM to write, design, or coach me through any part of it, is that sufficient to meet a project's "no AI" policy?
I think that I see that in the same way as I see other questions of provenance.
For instance, if I promise that I have the permission to contribute a patch, but I do not, that might be hard to detect, but is nevertheless important.
-
@neil also as a developer, it might be hypocritical to say absolutely no to AI.
There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.
For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.
I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.
So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."
If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil i'm personally going to wait a while. these new rules mean that contributers are responsible for ensuring their contributions are copyright-free, and AFAIK debian's semi-militant "foss-only" stance remains in play.
is this going to be a template for malicious compliance? "no, sorry, you can't prove you didn't use copyrighted code". — i don't know.
is this going to be a way to rubber-stamp non-foss code? — i don't know.
wait and see…
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil just use fedora
-
@neil i'm personally going to wait a while. these new rules mean that contributers are responsible for ensuring their contributions are copyright-free, and AFAIK debian's semi-militant "foss-only" stance remains in play.
is this going to be a template for malicious compliance? "no, sorry, you can't prove you didn't use copyrighted code". — i don't know.
is this going to be a way to rubber-stamp non-foss code? — i don't know.
wait and see…
@neil also, sadly, the vast majority of the code in a debian distro is not written by debian developers, and the way things are going _that_ is most likely to have been touched by the magic eight ball - including the kernel. so.
-
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."
If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)
@skjeggtroll
That's the key difficulty.But in the case of Debian, the main use will be (will, not could) solving dependencies, because that's the key problem facing "developers" (mostly packagers, the unsung heroes of FOSS, really).
-
@neil just use fedora
"just" does a lot of heavy lifting here.
-
@dequbed Thank you!
I have not used Gentoo in 25 years
