DevNews

Debian Adopts Responsible Use of Generative AI

On this page
  1. What Debian actually decided
  2. How the ballot got there
  3. What changes for you on Monday
  4. What it does not settle
  5. Sources and further reading

Debian has settled its generative AI policy: the General Resolution closed on Friday August 28, 2026 and the winning option is Responsible Use of Generative AI. The project neither endorses nor prohibits AI tools. Every contribution meets the same standards of quality, correctness, maintainability and legal compliance regardless of how it was produced, the contributor remains fully responsible for what they submit, and disclosure of AI assistance is encouraged but not required. The two prohibition options lost, one of them badly. The result is a position statement issued under Constitution section 4.1 (5), which means it can evolve later without another vote.

The short answer

Debian's General Resolution on LLM usage closed on Friday August 28, 2026 and the secretary published results just after midnight UTC. The winning option is Responsible Use of Generative AI: the project neither endorses nor prohibits the tools, contributions are held to the same standards whatever produced them, the contributor stays responsible for what they submit, and disclosure of AI assistance is encouraged rather than required. The outright ban, which needed a three to one supermajority because it amended the Social Contract, finished at a ratio of 0.560.

Option 5Responsible Use of Generative AI, the winner
425unique voters, from 575 ballots received
0.560the ban option ratio, where 3.0 was required
Answer card summarising the Debian General Resolution result: Option 5, Responsible Use of Generative AI, won the vote that closed on August 28 2026, with 425 unique voters, no ban on AI tools, contributor responsibility unchanged, and disclosure encouraged but not required.
The Debian generative AI vote, in one card. PNG

Two weeks of voting, nine options on the ballot, and the answer turns out to be the one that changes the least. That is usually a good sign in a governance vote.

What Debian actually decided

The adopted text is a position statement, not a rule change. Debian neither endorses nor prohibits generative AI tools in the development, maintenance or documentation of anything published within the project. It recognises that the tools can meaningfully improve contributor productivity when used responsibly, and frames that in terms of volunteer time: less of it spent on mechanical work, more of it on the parts that need expertise, judgement, review and collaboration.

Then it draws the line. Every contribution submitted to Debian has to satisfy the same standards of quality, correctness, maintainability and legal compliance, regardless of how or with which tools it was produced. Using a generative tool does not reduce the contributor's responsibility for the work. Contributors are expected to understand, review, test and where appropriate modify the output before it goes anywhere near the archive, and accepting or uploading generated material without human review is described as inconsistent with Debian's established practice.

On disclosure, the project encourages contributors to say when a contribution was AI assisted, and stops there. It is not a requirement.

How the ballot got there

The vote opened on August 15 with eight competing proposals plus none of the above, after months of argument on the development lists about what an LLM policy should even look like. It closed at 23:59 UTC on August 28 and the secretary's scripts produced the result at 00:01 UTC on August 29.

Comparison chart of the Debian LLM General Resolution ballot showing votes against none of the above: Responsible Use of Generative AI at 281, a cautious approach at 276, allow with conditions at 267, reject as far as practical at 176, and the Social Contract ban at 144 against a required three to one supermajority.
Pairwise results against none of the above, from the project secretary's tally. PNG

The turnout numbers: 575 ballots received, 499 passing signature and directory checks, 438 tallied, 425 unique voters. Quorum was 47.24 and every option cleared it comfortably, so nothing was decided by apathy.

The interesting part is where the prohibition options died. The strict ban worked by amending the Social Contract, which is a foundation document, so Debian's constitution demanded a three to one supermajority. It finished at 144 votes against 257 for the default, a ratio of 0.560 against a bar of 3.0. Not close. The softer version, which would have rejected LLM use as far as practical and amended the Code of Conduct, needed only a simple majority and still failed it at 176 against 230.

Among the surviving options the contest was genuinely tight. Responsible Use beat the conditional acceptance proposal by 203 to 148, and beat the cautious approach proposal by 210 to 130. The Schwartz set at the end contained exactly one option, which is the cleanest possible outcome for a Condorcet ballot with nine choices on it.

What changes for you on Monday

If you maintain packages, very little, and that is the point. Nothing in the adopted text hands you a new obligation, a new form to fill in, or a new field in the changelog. What it does is remove an argument: a reviewer can no longer reject your work purely because a tool was involved, and you can no longer defend a broken patch by pointing at the tool.

Where it will bite is on volume. Debian's package archive and bug tracker sit downstream of the same pressure the Linux networking subsystem has been describing all year, where the constraint is not whether a patch is machine assisted but whether a human reviewer's time is being spent well. The adopted text puts that burden squarely on the submitter, which is the only place it can sit without breaking the project.

Teams inside Debian remain free to be stricter within their own workflows. The resolution is a project wide floor, not a ceiling.

What it does not settle

The legal question stays open, deliberately. The text acknowledges that the status of generative output is still unsettled across jurisdictions on copyright, authorship, licensing and the reproduction of training material, and states plainly that the project is not resolving those questions here.

That is the honest position, and it also means the existing licensing discipline is unchanged. Debian's archive has always demanded that everything in it can be licensed under terms the project accepts. A contribution that cannot meet that bar does not get in, and no vote about tooling changes that.

Because it was issued under Constitution section 4.1 (5), the statement can be revised as the situation moves, without dragging the project through another General Resolution. Given how fast this particular ground shifts, that flexibility may end up mattering more than the wording itself.

Sources and further reading

Frequently asked questions

Does this mean Debian now accepts AI generated packages and patches?

It means Debian will not reject a contribution on the sole ground that a generative tool helped produce it. That is a narrower statement than acceptance. The adopted text is explicit that every contribution has to satisfy the same standards of quality, correctness, maintainability and legal compliance as any other, and that the person submitting it carries the full responsibility for it. Uploading output nobody understood, reviewed or tested is described as inconsistent with how Debian develops software. In practice a maintainer who cannot explain and defend a patch is in the same position they were in before the vote, which is to say a bad one.

Do I have to disclose that I used an LLM on a Debian contribution?

No. The adopted option encourages contributors to disclose AI assistance but explicitly stops short of requiring it. That distinction was one of the real dividing lines on the ballot, since several competing proposals wanted mandatory disclosure or mandatory provenance tracking. Disclosure remains a good habit for a reviewer's sake, especially on large diffs or on packaging changes where a reviewer's attention budget is limited, and individual teams inside Debian remain free to ask for more within their own workflows. The project as a whole simply does not impose it.

Why did the outright ban option lose so heavily?

Two reasons, one procedural and one arithmetic. The ban proposal worked by amending the Social Contract, which is a foundation document, and under Debian's constitution that requires a three to one supermajority rather than a simple majority. It finished at 144 votes against 257 for the default option, a ratio of 0.560 where it needed 3.0, so it was dropped for failing majority. The softer prohibition option, which would have rejected LLM output as far as practical and amended the Code of Conduct, did not clear a simple majority either, finishing at 176 against 230.

Does the resolution settle the copyright question around AI generated code?

No, and it says so directly. The adopted text acknowledges that the legal status of material produced by generative systems is still being argued out in many jurisdictions, covering copyright, authorship, licensing and the possible reproduction of training material, and states that the project is not trying to resolve those questions through a General Resolution. That leaves the existing licensing obligations exactly where they were. If a contribution cannot be licensed cleanly under the terms Debian requires, it does not get in, whatever produced it.

Can Debian change this policy without another General Resolution?

Yes, and that was deliberate. The statement was issued using the power in Constitution section 4.1 (5), which lets the project issue a position statement, and the text says outright that the position describes where the project stands at the time of adoption and may evolve as time passes without needing a future General Resolution. The GR process stays available if the project needs a binding decision and cannot reach consensus. In other words this is a settled direction rather than a locked constitutional rule.