Debian puts LLM use in its contributions to a project-wide, eight-option vote
From August 15 through August 28, 2026, Debian Developers are voting on a General Resolution governing LLM use in the project’s contributions, with eight proposals and a “None of the above” option. The outcome will set a de facto standard for the supply chain of enterprise Linux distributions.
August 15, 2026. Debian opened voting on a General Resolution titled LLM usage in Debian. August 28, 2026. The ballot closes, ending thirteen days in which only Debian Developers may rank eight proposals plus a “None of the above”. For an SRE or CISO who consumes Debian as infrastructure bedrock, the stakes are not folklore: this is the first time a major distribution has put “how much AI in the code” to a project-wide, structured vote.
The result will not change the binary you download tomorrow. It will change the answer to a question that does concern you directly: when a Debian maintainer merges a patch, can you assume a human understood it?
Eight proposals, one full spectrum
The ballot carries eight proposals (labeled A through H on the voting page), settled by Debian’s usual ranked voting — a Condorcet-style system in which each voter orders their preferences. Eight texts that do not merely oppose “for” and “against”: they draw a full spectrum, from outright ban to studied neutrality.
Proposal A is the hardest line. It amends the Debian Social Contract to ban LLM-assisted contributions to the project’s direct work — packaging, software, documentation, translations, websites, communication. Upstream projects developed with AI would be unaffected, but what enters Debian itself would have to be written by humans. Its advocates cite unclear copyright and licensing, the doubtful reliability of generated code, the extra review burden on maintainers, the aggressive scraping of Free Software resources, and the energy footprint of large models.
Proposals B, D, and E allow AI but shift the responsibility. B requires the contributor to verify the technical quality, security, licensing, and usefulness of what they submit, to fully understand the changes, and to disclose any major LLM help — while banning the sending of private or sensitive Debian information to untrusted external AI services. D accepts assisted work if it complies with the DFSG, is reviewed and understood by the contributor, and is marked as such where needed. E, the most neutral, refuses to support or ban generative AI tools: it applies the same standards of quality, correctness, maintainability, and legality to every contribution, regardless of origin.
Two proposals step outside the binary frame. F, titled “Debian is created by humans”, allows AI for research, analysis, exploration, or critique, but forbids submitting a model’s output directly as Debian work — patch, package, documentation, bug report, or communication. H puts the environmental argument at the center: it asks contributors to avoid LLMs as much as possible, on the grounds that their resource use is a serious environmental issue, while conceding that AI detection is unreliable and that Debian cannot constrain its upstream projects.
Finally, G hardens communication: bug reports, mailing-list messages, Salsa discussions, and Planet Debian posts would have to be human-written, any AI use in Debian work disclosed, and violations handled under the Code of Conduct.
Why this vote reaches beyond Debian
Debian is not the first Free Software project to settle the question — it is the largest to pose it this clearly. The recent context is a run of divergent positions: Rust adopted an official policy on AI-generated contributions, Gentoo enacted a ban, GCC rejects significant generated code, Codeberg banned projects written mostly by generative AI, and Fedora tabled a policy proposal. Each project decides alone, with no shared precedent.
What makes the Debian case singular is its place in the supply chain. Debian is not a language or a forge: it is a distribution that aggregates tens of thousands of packages and serves as the base for entire derivatives — Ubuntu, a large share of the cloud, and enterprise infrastructure. The standard Debian sets for “what may enter the project” becomes, by capillary action, a de facto standard for everything built on top of it. A CISO who demands contribution traceability from vendors will read the final resolution as a precedent.
There is also an internal dimension of precedent. Debian has voted before on a resolution about the DFSG interpretation for AI models — since withdrawn. So the question “does generative AI belong in the project” returns in a more operational, less philosophical form: not “is a model free”, but “who answers for a contribution produced by a machine”.
The real fork, and what to watch
Under the profusion of eight texts, the real divide is simpler than it looks. On one side, A starts from the principle that a generated contribution is irreparably suspect — you can neither establish its authorship, nor guarantee its license, nor prove its comprehension. On the other, B, D, and E start from the principle that a contribution is worth what the human who signs it understood and accepted — the tool is secondary, the responsibility is primary.
Between them, F attempts an original line that could become the compromise position: AI assists the human’s work, but it does not produce the artifact that enters Debian. In hollow, that is the distinction many engineering teams already practice without formalizing it — AI to understand, humans to decide and sign.
What to watch is less the winner than the margin and the quorum. A resolution imposing the ban on a narrow majority will leave part of the project durably at odds, and the question will return. A resolution that records contributor responsibility without an enforcement mechanism will change almost nothing in practice — it will ratify the status quo under official vocabulary.
Verdict
If you are a Debian Developer, the vote is your lever and it closes on August 28, 2026: rank all eight options, and read A and F in full before you decide — they are the two texts that will define the ridge line of the debate, whoever wins.
If you run Debian in production, do not treat this as an internal community matter. Record the result, then ask yourself the governance question that follows for your own chain: do you have a written policy on AI-assisted contributions in the packages you assemble and deploy? Debian’s answer is about to become a convenient benchmark for your own vendor requirements.
If you publish software, read the position that emerges from the vote as an indicator of market expectation: the heavy trend, at Rust, GCC, and Gentoo as much as Debian, runs toward explicit human responsibility — transparency about a contribution’s origin is becoming a trust requirement, not a communications option.