Debian’s AI code policy does not ban contributors from using generative-AI tools in work submitted to the Linux distribution. The position adopted by the project leaves those tools permitted across development, maintenance, documentation, packaging and other material Debian publishes, while putting the ordinary obligations for a submission squarely on the person who sends it.
That is a narrower outcome than an AI endorsement, and less dramatic than a blanket prohibition. According to GamingOnLinux’s reproduction of the adopted resolution, Debian says generative AI gets no special exemption and no separate rulebook beyond the standards contributors already face. The Verge reported that Debian’s voting developers considered alternatives that included a ban on AI-made contributions.
What does Debian’s AI code policy require?
A contributor using an AI tool is expected to understand the result, review it, test it and modify it where needed before adding it to Debian, according to the resolution reproduced by GamingOnLinux. Uploading generated material without appropriate human review conflicts with Debian’s established development practices. Quality, correctness, maintainability and legal compliance remain required regardless of the tool used.
In practical terms, the policy treats AI assistance as part of a contributor’s workflow, not as a new author that can carry the blame when a patch breaks a package or arrives with unclear rights. The submitting contributor remains accountable for the material’s technical quality, legal acceptability and suitability for Debian.
- Contributors may disclose AI assistance, but Debian does not require that disclosure.
- Existing rules on licensing, copyright, software freedom and accepting contributions still apply.
- Contributors should consider a submission’s provenance and licensing, and avoid material whose legal status they cannot reasonably justify.
- Confidential, private or security-sensitive Debian information, along with credentials, cryptographic keys and other non-public material, must not go to third-party AI services unless that is explicitly authorized and consistent with project security and privacy requirements.
The resolution does not attempt to settle the harder legal question hovering over generated output. GamingOnLinux reported that Debian expressly declined to take a position on unresolved questions involving copyright, authorship, licensing and whether an AI system may reproduce training material. Permission to use a tool is not a declaration that every output has clean provenance.
The policy also puts limits on automated work at project scale. Mass bug reports, patch submissions, widespread code changes and other actions affecting many packages or contributors should be discussed through the appropriate Debian channels first, with consensus and human oversight, according to the reproduced resolution. Automation does not get to skip the part where maintainers have to live with the consequences.
Reaction has not been uniform. The Verge reported objections from some users and contributors. It’s FOSS reported that Debian developer Antoine Le Gonidec said he would leave the project over the decision. The adopted policy, however, does not create a special fast lane for AI-generated code. It preserves the existing gate: a human contributor must be able to stand behind what enters Debian.
This story draws on original reporting from The Verge.