Debian permitting use of genAI:
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil I am not overly surprised by this, it is a pragmatic rather than political approach. Banning LLM use is a lot harder (impossible) to police than the whole Debian "free software" stance.
It is a little disappointing that Debian of all distros couldn't have chosen to take a moral high ground on this though, as futile as it may be.
LLM/GenAI is super accessible, it has replaced search for many developers, because search is broken, the next step to having it generate code is a small shift from copy-pasting the odd line from docs or websites. So much coding is gluing together boilerplate and examples anyway. They could have "banned" GenAI use in Debian code, but this would never have stopped GenAI use in Debian code.
The current environmental and economic issues of LLM/GenAI are worth making a stand about though.
As a fairly pragmatic Debian user of some 30+ years I am conflicted. Though as a developer, for work purposes, I do make use of LLM tech — so I am myself tainted.
-
@mindpersephone @neil Having been anticipating starting from scratch anyway I'm trying to look at it as a chance to have some fun and frustration. I'm sure I'll learn a lot from it (I always used to find niche distros good for that, rarely found they work out the box) and I now have the free time for good old fashioned fucking around
Hannah montana linux first tho obvs
-
@voidandcozy @neil I haven't just yet but I've given myself a shortlist to explore. AerynOS, redox, 9front, elementary and haiku
-
@neil I am not overly surprised by this, it is a pragmatic rather than political approach. Banning LLM use is a lot harder (impossible) to police than the whole Debian "free software" stance.
It is a little disappointing that Debian of all distros couldn't have chosen to take a moral high ground on this though, as futile as it may be.
LLM/GenAI is super accessible, it has replaced search for many developers, because search is broken, the next step to having it generate code is a small shift from copy-pasting the odd line from docs or websites. So much coding is gluing together boilerplate and examples anyway. They could have "banned" GenAI use in Debian code, but this would never have stopped GenAI use in Debian code.
The current environmental and economic issues of LLM/GenAI are worth making a stand about though.
As a fairly pragmatic Debian user of some 30+ years I am conflicted. Though as a developer, for work purposes, I do make use of LLM tech — so I am myself tainted.
@neil hm, I should have said near-30 yers lol. My first Debian install was 1998! So more like 28 years. But... details. It has been a long old time, albeit with a slight Ubuntu dalliance on desktop for a bit.
The developer perspective is the hard one right now. LLM generated code is entering the "corpus" of knowledge whether we like that or not, whether we use the tools or not. Probably a majority of developers in the world are using it, with those of us uncomfortable with it being a small niche, and those who take the harder stance of not touching it being an even tinier niche.
It is simply no longer possible to guarantee anything is free of LLM content/influence unless you have 100% written it yourself with no non-textbook/fundamental reference material. (And given time even the books and core references will be tainted in many cases.)
There is no way to tag or otherwise identify a line of code as LLM tainted.
-
@voidandcozy @neil Fedora accepts AI assisted contributions so not one that I'm interested in looking at. I also haven't tried it in a very, very long time so I can't really give an opinion on it in terms of user experience
-
@skjeggtroll
That's the key difficulty.But in the case of Debian, the main use will be (will, not could) solving dependencies, because that's the key problem facing "developers" (mostly packagers, the unsung heroes of FOSS, really).
@iinavpov @skjeggtroll @neil do I understand it correctly though that Debian now could conceivably allow new packages that are say largely written by an LLM?
-
@neil I think "environmental harm" needs to come with some sort of disclaimer.
In the US, yeah, I have no idea how the way they're building datacenters there is legal.
Here in Sweden they run on 100% renewable energy and don't use up water.
I feel the whole environmental debate around LLMs has centered on what happens in the US, with very little actual data shown.
https://ourworldindata.org/how-much-energy-do-data-centers-and-artificial-intelligence-use
@troed @neil Gut feeling / educated guess? Swedish usage is less than 1 % of US usage and US practices are more widely spread in the world due to the sheer monetary pressure and influence.
I'm fairly certain Sweden is the unicorn in this, working enforcement is still quite rare in the rest of the world, even if regulations exist. EU countries are rich and can afford it, most countries focus on primary needs like health and education.
China seems all in for the surveillance value, no limits.
-
@troed @neil Gut feeling / educated guess? Swedish usage is less than 1 % of US usage and US practices are more widely spread in the world due to the sheer monetary pressure and influence.
I'm fairly certain Sweden is the unicorn in this, working enforcement is still quite rare in the rest of the world, even if regulations exist. EU countries are rich and can afford it, most countries focus on primary needs like health and education.
China seems all in for the surveillance value, no limits.
"China seems all in for the surveillance value, no limits."
China release their LLMs as open weights, meaning others (like Mistral in France) can run them in their own datacenters.
For some reason (and I have a guess) China is spending a lot of money making sure the world has access to extremely capable Frontier level AI at only the cost of hosting them.
I run such a model myself, on my own GPU in my dev workstation. The energy usage is thus the same as when playing a game.
-
@voidandcozy @babe @neil Fedora is owned by fascism and Gen AI loving IBM. Yuck!
-
@neil just use fedora
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil I can't actually recommend that you wade in very far, but if you do, you will see that many developers voted for options that focused on environmental (and other harms) of AI. It just happens that the winning option chose to pretend those harms don't exist. It's like "shitty elected leader $Y of country $X"; as a non-$Y supporter you have to live not only with a shitty leader, but also the reputational damage to being from country $X.
-
@happyborg@fosstodon.org @neil@mastodon.neilzone.co.uk @freshstart@hachyderm.io
there's no responsible use of such a problematic tech IMO
"Use open models, if you don't like these big companies' monopolies" -> still polluting the planet, stealing water from living beings, not being the author of what you submitted and in risk of DMCA takedown, trained without consent
"Yah, well use an open model locally then! You can employ renewable energy!" -> training the model is still polluting the planet, stealing water from living beings, still not being the author of what you submitted and in risk of DMCA takedown, trained without consent
"Ah well, it's already trained, just ignore that fact. I mean it's such a helpful technology" -> still not being the author of what you submitted and in risk of DMCA takedown, trained without consent
"OKOK, that argument does not stand. There is no single DMCA takedown or judge that decided it's not yours!" -> trained without consent
You know what kind of people don't like consent of people in weaker positions (minorities, poor, neurodiverse)?....yah...
I'll also have to check what alternatives there are.... -
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
@neil I need to read it. On point 2, I think it's going to be more or less impossible to pursue claims over time, I can't envisage a scenario where an organisation can sue on the basis an AI was used and that AI copied their work, when they're almost certainly using AI themselves! On point 3, I think it's a massive missed opportunity to not put some eco requirements into policy - it would be hard to enforce, but it would draw a line and would make people think at least.
-
@neil I need to read it. On point 2, I think it's going to be more or less impossible to pursue claims over time, I can't envisage a scenario where an organisation can sue on the basis an AI was used and that AI copied their work, when they're almost certainly using AI themselves! On point 3, I think it's a massive missed opportunity to not put some eco requirements into policy - it would be hard to enforce, but it would draw a line and would make people think at least.
@neil Also, as the director of a company with about 200 Debian servers I have no idea what to do with this right now... 🤯
-
@neil @tschenkel worked for Joey Hess!
@davidgerard @neil @tschenkel I'd love to join you all but unfortunately my body relies on products by big pharma to continue to function as well as it can. So please don't all just depart but leave some sane people who know how to take care of the tech which is still important to some of us, TIA!
-
Debian permitting use of genAI:
1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.
2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.
3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.
4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.
I bet they are obligated to do so. Let's go back to Hannah Montannah Distro, as the best of both worlds
-
@neil Also, as the director of a company with about 200 Debian servers I have no idea what to do with this right now... 🤯
@neil Somewhat related: I had to write @codeenigma's AI policy this year, on consultation with colleagues and peers of course, which was interesting.
It ended up being "unless there's a strong business case, don't" i.e. you need to be able to prove "AI will definitely make this better". Coupled with "here's a list of permitted AI services and models, you may not use any others". The second part attempts to minimise environmental impact, we added environmental credentials to supplier selection.
-
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."
If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)
@skjeggtroll @freshstart @neil it's worse than this actually.
We know that LLM code sometimes includes fragments of training data verbatim. We know much training data is licensed such that verbatim copies requires attribution. So we know that LLM code sometimes violates these attribution requirements.
There is no practical way to check whether a given section of LLM produced code violates an attribution requirement. How are you going to search against all lines of code in the training database? Do you run that search for each line of code?
Even worse: two different people using the same LLM, even with different prompts, may generate the same or substantially similar code. Whoever tries to slap a license on that code second is in violation of the first person's license, assuming a world in which such code is licensable at all. These people probably don't know of each others' existence at first. This has already happened, see:
https://blog.terrygodier.com/2026/08/09/mea-culpa-dark-hours.html
To accept any LLM-generated code or documentation is to say that you are fine with license violations. If, as Debian did, you try to thrust the impossible burden of ensuring license violations do not occur onto each contributor, I'm not sure what you're saying, but your policy isn't sincere.
-
For a reasoned, contrary point of view please see this thread:
-
@neil Well, with even the Linux kernel accepting the use of LLMs... maybe it's time to start looking towards BSD, maybe even specifically NetBSD as they seem clearest on the case.
Code runs deep and sometimes fast and so does this issue.

️