Flathub drops its AI-code ban and requires Linux maintainers to disclose AI use
In early October 2026, Flathub replaced its blanket ban on AI-generated content, in force since May, with a mandatory disclosure policy. Maintainers must declare generated parts, but Flatpak manifests and automated submissions remain strictly forbidden.
In May 2026, Flathub, the Flatpak app repository for Linux, banned all AI-generated or AI-assisted code, documentation and material. In early October 2026, the project reversed course: the blanket restriction is replaced by mandatory disclosure. Maintainers must declare the generated parts, but Flatpak manifests and automated submissions remain strictly forbidden. Why it matters: this is the first major Linux repository to move from prohibition to “declare, and we judge.”
From a blanket ban to mandatory disclosure
The May policy was simple: any app containing AI-generated or AI-assisted code, documentation or packaging was rejected, with narrow exemptions for mature, well-maintained projects. The new policy inverts the logic. A maintainer can now submit an app containing AI-generated material, provided they disclose it — code, documentation, packaging and other components — and identify the affected parts and their approximate extent.
The nuance that matters: disclosure does not guarantee acceptance. Flathub reviewers can still reject an app based on the amount or role of generated content, concerns about code quality, or difficulty reviewing and maintaining the project. A submission can also be rejected without further review. Automatic rejection disappears, but human judgment remains the gate.
The policy also draws a line between generated material included in an app and AI tool use during development. Using AI for research, discussion or debugging requires no disclosure, as long as no generated material ends up in the app or its Flathub packaging. That distinction is what makes the rule workable: it targets what is shipped, not what helped produce it.
What stays forbidden, without exception
Two red lines remain, and they are firm.
The first concerns Flathub manifests. These files describe how an app is built and packaged as a Flatpak; they must contain no AI-generated or AI-assisted content, even with disclosure. The reasoning is technical: the manifest is the surface of trust reviewers rely on to audit a build, and a machine-produced manifest is harder to audit than one written by a human who owns its logic.
The second concerns submission automation. Flathub forbids using AI tools or agents to open or automate submission pull requests, generate commit messages and descriptions, or produce review comments and replies. Requesting an AI-agent review is also forbidden. Review must remain human.
Sanctions are graduated. Failing to disclose generated material or misrepresenting its extent exposes a rejection. Repeated violations can lead to a permanent ban from submissions and related activities.
Why the reversal, and what it says about the ecosystem
Context helps read the move. Flathub is not alone: in recent weeks, System76 announced that COSMIC stops accepting LLM-generated content in pull requests, Solus adopted a formal AI contribution policy, and Pop!_OS banned AI-generated contributions. The Linux world is choosing its rules against vibe coding, and every project arbitrates differently between outright rejection and constraint.
Flathub apparently concluded that a pure ban was not tenable at the scale of a public repository receiving hundreds of submissions. A total prohibition encourages concealment: a maintainer who wants to ship AI-assisted code only has to stay quiet. A disclosure policy turns concealment into a detectable, punishable offense, while keeping the door open to well-made generated content.
Keeping a hard line on manifests and automation reveals the real fear: not generated code itself, but the loss of legibility in the chain of trust. A repository lives on its reviewers’ ability to understand what they accept. The manifest and the review are the two places where that understanding happens — which is why they stay protected.
A policy choice, not an accident
Flathub’s pivot is part of a wider movement sweeping the Linux world. In a few weeks, System76 announced that COSMIC no longer accepts LLM-generated content in pull requests, Solus formalized an AI contribution policy, and Pop!_OS banned AI-generated contributions. Every project arbitrates between outright rejection and constraint, but they all converge on one demand: transparency about what a machine produced.
What sets Flathub apart is scale. A public repository receiving hundreds of submissions cannot verify, on every pull request, whether a block of code was written by a human or by an AI. A total ban was therefore either unenforceable or bypassed through silence. Mandatory disclosure changes the contract: it shifts the burden of proof onto the maintainer and turns concealment into a detectable offense, rather than pretending to make it impossible.
The underlying message holds for the whole ecosystem. What gets rejected is not AI-assisted code as such, but AI-assisted code that is undeclared, poorly reviewed, or shipped through a chain of trust that has become illegible. The difference between a tool and a risk lies less in the origin of the code than in the ability of those who accept it to understand it. A repository lives or dies on that legibility, which is why Flathub keeps manifests and human review as hard boundaries while relaxing the rest.
The practical stakes are concrete. A maintainer who quietly ships AI-generated code now risks rejection and, on repeat offenses, a permanent ban from submissions — a far heavier consequence than the rejection alone. For the honest maintainer, the new rule is close to costless: declare the generated parts, hand-write the manifest, keep the review human. The only people who lose are those who wanted the convenience of automation without the accountability of disclosure, and Flathub has decided that trade-off is no longer acceptable.
What maintainers should do
The practical consequence comes down to three points.
- Declare what is generated. If AI-produced code, documentation or packaging is part of your app or its Flathub packaging, identify the affected parts and their approximate extent. An honest declaration protects more than an omission.
- Write the manifest yourself. The Flatpak manifest must be free of generated content, no matter what. It is the first file reviewers audit.
- Keep the submission human. Do not automate the pull request, the commit messages or the review comments with AI. Review is a human act, and that is exactly what the policy protects.
For the reviewer, nothing changes in intent: accepting remains a judgment about quality and maintainability, not a mechanical validation of disclosure. What the new policy really buys is a paper trail: when a low-quality, AI-heavy app slips through, the disclosure record is what lets the project trace who shipped what and hold the maintainer accountable. A declared, labeled patch is also faster to audit than an anonymous one, because the reviewer knows where to look first.
Verdict
If you maintain an app on Flathub, the rule is easy to integrate: declare AI-generated material, write the manifest by hand and keep the submission human — you stay compliant and protect your submission history. If you thought lifting the ban opened the door to mass vibe coding, think again: reviewers keep the right to reject on quality and maintainability, and misleading disclosure remains an offense punishable up to a permanent ban. Flathub’s message is clear: AI-assisted code is tolerated if it is honest, but the chain of trust is non-negotiable.
References
- Linuxiac — Flathub Reverses AI-Generated App Ban, Now Requires Disclosure, October 2026
- Flathub — revised policy (GitHub commit)
- Flathub — manifests free of AI content (GitHub commit)
- Linuxiac — Flathub Now Rejects AI-Assisted Apps and Submissions, May 2026
- Linuxiac — COSMIC Stops Accepting LLM-Generated Content in Pull Requests, October 2, 2026