Debian permitting use of genAI:

1) I am surprised. Perhaps I am naive, but I was of the impression that Debian would be one of the last distros that would want this.

2) I agree that the legal position varies around the world, and is subject to change. I don't know how easy it would be to remove genAI code if the risk profile changed.

3) I am surprised how little weight is given (by anyone, not just Debian devs) to the environmental harm of genAI. Perhaps that is justified as being too remote to be of direct concern.

4) As a long term Debian user impacted by this decision, I need to make a decision. Not doing anything is a decision in itself, even if a temporary decision. Moving from Debian would be many days of work, but that doesn't mean doing so is the wrong decision for me. Aargh.

in reply to Kim Spence-Jones 🇬🇧😷

@KimSJ @voltagex Non-Linux I guess as the Linux kernel allows for AI contributions.

I am trying NetBSD first and see how I get on. I am under no illusions that it will be harder than continuing with debian and its derivatives.

I have been using debian based OSs since I installed eeebuntu on my first eeepc in 2009, and every device I own currently uses one or another flavour of the debian family.

It will take a while to lose the "sudo apt update" muscle memory.

docs.kernel.org/process/coding-assistants.html

in reply to Neil Brown
My thinking is that it sucks a great deal, but it's not something that I need to rush to deal with. I'm already using openwrt a lot more at home (I used to have a wifi AP running debian), and most of the AI use that I've seen so far has been more on the infrastructure side (dak, voting software, etc) than individual packages. But I'm going to start investigating other distributions..
in reply to David Gerard
@davidgerard @tschenkel I'd love to join you all but unfortunately my body relies on products by big pharma to continue to function as well as it can. So please don't all just depart but leave some sane people who know how to take care of the tech which is still important to some of us, TIA!
in reply to Neil Brown

we're going to need a lot of log cabins @tschenkel

I'm about to set up a new media server (I wish I'd bought the ram last year), and was already looking for a non-systemd distro; then Linus says slop is OK in the kernel, so I'm seriously wondering if I'm moving to a BSD. I've used a BSD-based NAS distro before, but there are a few things I don't know about right now, and it's also another way of thinking about the whole system setup & updates (I /like/ apt as a package system)

in reply to tschenkel

@tschenkel Good question - anyone?

I *was* planning to move to Linux - prob MintLinux - but now I'm not sure as it seems AI, (well, LLMs anyway), is going to turn up embedded in all Linux based OS's.

My problem is that I don't know much about Linux other than the little I learned about OG Unix - my intention was to learn as I used it.

Now, it feels like checkmate 😔, so any advice on where I can turn would really be appreciated...please?!!!

in reply to Oyu F'ka

@Oyu_Fka
I don't think the problem is that LLMs are going to be embedded in Linux. At least not in the same inescapable way they are in Windows and OSX - they will be available, but mostly not installed by default, and if they are (some distros may include them, but Mint likely won't) they will be ee easy to disable.

The problem in this thread is that many Linux distros had "no AI code in core elements" policies, which are now eroded.

in reply to tschenkel

@tschenkel Thanks for the reassurance! Tbh, it's early days yet...I have to buy a second hand laptop first, lol!

I'll carry on reading up on Mint in that case - it was the fact, as you say, that AI is being allowed into the cores of some distributions that bothered me, particularly with open source products...🤔maybe I'm over thinking, (again), lol!

in reply to tschenkel

@tschenkel My initial interest in moving to Mint, (or Linux generally), was privacy, but I grew concerned due to the increasing integration of LLMs which could compromise that, either through poor coding/design, or worse still, deliberately in the way google operates...or even other actors with even more nefarious purposes.

Anywayz, I'll put my cynicism away and get back to Mint 👍!

in reply to Neil Brown

I'm with you on this. It's going to take me months to move to a new OS, and anything I can think of, will probably be Debian based, because I'm so tied to apt for so many things right now. These are all the (linux based) OSes that I'm aware of that have either no policy on LLMs, or in some special cases, have explicitly banned LLMs:
codeberg.org/ethical-foss/open-slopware#alternative-linux-based-operating-systems

Debian has taken a decision that will really just poison several layers down, which hurts a lot. I already have a few forks of other tainted software that are large enough, that I can't really take on more, but I really hope someone forks Debian... I don't think Debra and Ian would have wanted this.

Esta entrada fue editada (hoy, 6:21)
in reply to Frank

@fschaap
bsd doesn’t support a host of hardware drivers, we cannot run away from this. maybe in the short term but we cannot keep hopping distros and systems to avoid this. I don’t want to say the ai sloppers won but at least for now our entire field is under slop occupation unless we actually do something about it.

hooligans don’t just get bored and leave, especially if you don’t start forcing them out..

Esta entrada fue editada (hoy, 11:05)
in reply to Tim Small

@tim Neil said his opinions are for another day.

Personally I think LLM/AI can be a useful tool, but right now we're at the stage where global production goes whee! this stuff is amazing and does all these cool things, but it's leaking crap into the environment like PFAS, microplastics, CO2 and chlorofluorocarbons, and yes, plenty of people are calling it out, but we all still want and use fridges, cars, packaged food and nonstick pans. So yeah... what do you do?

in reply to Neil Brown

went through the same cycle yesterday, but the only system I saw which is hard "no" mentioned was NetBSD which, tbh, looks a pain to use.

After pondering, I think the real issue for me isn't Debian, it's the kernel. Linus and the foundation opening that door means *every* Linux distro is "tainted". I see no issue with a distro allowing it if I can actually move to one that doesn't, but the kernel is the kernel. 🤬

in reply to b3lt3r

@b3lt3r
NetBSD is not really harder than Linux when you know how to use the basic system (shell, vi, emacs, etc).

And your notice regarding the Linux Kernel and genAI can also be transferred to FreeBSD. This is also mainly a kernel only, most of the programs use nearly identical source code as used on Linux.

So to my example on the other toot, just imagine Wayland or X11 having genAI inside, would mean you could not use any OS for a workstation anymore.

in reply to Yer Feff

@feff Yes, and perhaps I should have been "on this" sooner.

I could do nothing, adopt a watching brief, and pretend that that makes me neutral on the topic.

And doing nothing is definitely superficially attractive, because the doing something meaningful is a huge amount of work.

I'm pretty sure that even our doorbell runs Linux.

in reply to Neil Brown

I don't feel like doing nothing neccessarily means taking a neutral stance, but I get you.

I think my current plan is to just continue until it becomes impossible to use my Surface, although my choice pof doing so is not an endorsement (just a reflection of powerlessness and persuasiveness of the tech). I don't really have the time for distro hunting now, especially as an artist with specialist software.

in reply to Neil Brown

thanks Neil for your thoughts.

So Debian in the past has done some possibly questionable decisions like systemd.

I am aware of the environmental harm that AI is doing. On the other hand I can imagine a future where we all run a low resource local AI on better hardware and where there isn't so much money being pumped into these data centers anymore. However nobody knows the future and the sooner these firms go bankrupt, the sooner that there will be some alignment between environmental cost and financial cost.

in reply to Neil Brown

also as a developer, it might be hypocritical to say absolutely no to AI.

There are some use cases that are compelling such as the way it can explain code to me or how can assist me with languages that I know but I am not good at yet for example rust.

For these use cases I would want to use some AI. And I imagine this is true of other developers. Even Debian developers. And that would be responsible use AI, right? This would not be creating slop necessarily.

I can understand that they also some cases where LLMs either by design, or due to insufficient oversight introduce security vulnerabilities into software and these I am concerned about.

So, umm... How to get the balance right? An outright ban for me is too much. But if it is allowed in limited and restricted circumstances only, wouldn't you say yes to that?

in reply to Jon

@freshstart
I would think that just based on license concerns alone would necessitate a policy of "No source-code or binary files may be generated wholly or in part by an LLM."

If _you_ didn't write it, or if you don't have a license to relicense it, you can't in good order publish it under an open-source license. (Or, for that matter, a closed-source license.)

in reply to Jon

@freshstart
Not more or less than yesterday.

Currently, because licensing is unclear, such a package may well face many extra hurdles.

but adding public domain code to your, say, GPL licensed project doesn't make it less GPL licensed.

Creating software mostly from public domain code and relicensing it is - I don't know, I'm not a lawyer. Weird certainly.

@skjeggtroll @neil

in reply to Skjeggtroll
in reply to Tiota Sram

@tiotasram@kolektiva.social

#Debian was structured as a democracy of developers (maybe technically a platonic aristocracy, but it does not matter here).

Thanks to this, it got trust that turned it into a fundamental building block for #Linux users (most used distro are Debian derivatives).

Unfortunately, such trust also attracted commercial interest.

Now most of Debian Developers (just like most of #Linux kernel's devs) are corporate employees that would not be assigned to Debian development if they would oppose corporare interests.

So ultimately Debian cannot be trusted anymore: the vote on #LLM is just an evidence of this fact.

To people who use it since decades (I started with Potato because of its focus on #freedom), it's a pain.

Right now I'm slowly moving to #NetBSD.

@skjeggtroll@mastodon.online @freshstart@hachyderm.io @neil@mastodon.neilzone.co.uk

in reply to Jon
in reply to Jon

@freshstart Why would
it be ‘hypocritical’ as a developer? Also as a developer, I don’t find it at all unreasonable to reject all those uses. (Personally I either find them unreliable, or at best not useful enough to justify the harms.)

So it seems like it’s about personal ethics and tradeoffs rather than any objective evaluation (for both of us).

@neil

in reply to Jon

@freshstart I wouldn't say yes to that. The possible utility of AI doesn't change the underlying ethics or environmental costs.

This reasoning is exactly what leads to shit like Operation Paperclip. It's okay if we let these people get away with their horrifying crimes as long as they help us with rockets, right?

Right?

You might not like it, but ignoring ethics because the tool is useful is this exact reasoning. Is it on the same scale? I dunno, maybe not yet, but it's the pure utilitarianism path, so, you know… be careful what you're stepping in.

in reply to Neil Brown

appreciate your thoughtfulness on this, even if I don't necessarily entirely share your values.

My issue with this whole thing comes down to detectability and trust. If I point at a git commit, authored by me, and I pinky swear I didn't use an LLM to write, design, or coach me through any part of it, is that sufficient to meet a project's "no AI" policy?

in reply to Neil Brown

I agree with that framing.

The provenance thing provokes the same question for me about where the line is though.

A hidden actor that writes the code directly that I claim? Probably against the policy.

Someone/thing that coaches me through writing the code? Someone who writes a blog/book that inspires me to create the code? Less clear.

What about a machine that takes the voice output of someone unable to type and turns that into code? Is that acceptable?

I don't think "no LLMs / no AI" is anything like precise enough to be useful. It's a good statement of principle, but a wholly inneffective policy imo. I have no good answer or suggestion though :(

in reply to Neil Brown

i'm personally going to wait a while. these new rules mean that contributers are responsible for ensuring their contributions are copyright-free, and AFAIK debian's semi-militant "foss-only" stance remains in play.

is this going to be a template for malicious compliance? "no, sorry, you can't prove you didn't use copyrighted code". — i don't know.

is this going to be a way to rubber-stamp non-foss code? — i don't know.

wait and see…

in reply to David Gerard

@davidgerard i disagree only with "at best". there is a _chance_ it will be used to block some or all slop code on grounds which a techboy who thinks they are "non–political" could not argue with.

on the other hand, this is broadly the same policy as adopted by the kernel. ***the kernel***.

if i want to be absolutist about this, time to switch to Haiku. i can't do that.

edit: i certainly would think well of anyone who can. i can't.

Esta entrada fue editada (hoy, 9:24)
in reply to Dragon

@Dragon The BSDs haven’t yet allowed LLM use for core contributions, but several accept it in upstream packages. E.g, OpenZFS has some commits “co-authored by” Claude, and FreeBSD includes OpenZFS. It’s not FreeBSD code, but the point of the BSDs is they ship a cohesive system, so it’s fair to assign them responsibility for what they ship.

OpenBSD’s stance is purely about code quality, and they haven’t seen LLM-generated code which meets their bar. They don’t tell people not to try, though.

NetBSD has a strong anti-LLM stance centered on the fact LLM-generated code can’t be BSD-licensed.

in reply to Neil Brown

3) is by everyone. A couple of years back, my employer asked everyone how they got to work, because they "needed" it for some ESG report, but AI is excluded from newer reports (and that is even legal) and if you mention it, you just get a lecture about how AI is a necessity for the future of the company. My unwillingness to use it outside of very narrow field already got me in hot water.

4) As another log time user, I decided to wait what happens to both Linux and Debian for a while.

in reply to Jörg 🇩🇪🇬🇧🇪🇺

@AlienJay it's not Linux, but #NetBSD has a policy forbidding what they call "tainted code": netbsd.org/developers/commit-guidelines.html

#Gentoo has a similar position.

Both allow individual exceptions to be made after careful review of all concerns.

in reply to Frontier Supermodel

@pikesley No really, I do. Because every single one of those externalities has been done by every single wave of major new tech.

Extreme pollution? Check.

Mass unemployment? Check.

Exploitation of the knowledge and skill of workers to create new capital? Literally the definition of capital, if you're Marx.

AI is very large quantity of past human labour — writing, drawing, code, argument, explanation, correction — compressed into an instrument that can be set to work. This is not new. Every machine is congealed labour. A power loom is the accumulated skill of weavers, abstracted from weavers, installed in a factory, and then used to make weavers cheaper. The nineteenth century worked out what happens next, in some detail, mostly by doing it to people.

So yes, it *is* capitalism I'm afraid. And capitalism's greatest trick is convincing a lot of people that it's not.

in reply to Frontier Supermodel
in reply to Ian Betteridge

@pikesley But here's the bit where I understand your objection

The general-framework argument -- it's all capitalism -- flattens differences that matter for policy, so that everything ends in "organise" and nothing ends in "meter the water", or "restrict AI", or whatever.

That's a fair worry about how the argument gets used, but it's not fair about the argument itself. Structural analysis tells you why a harm persists and who has to be beaten to stop it. It doesn't substitute for a specific technical or legal amelioration of the impact.

in reply to Frontier Supermodel
@pikesley @ianbetteridge Didn't you know? Exploding electricity bills for people living close to data centers are "a huge positive". Catching asthma from 24/7 screaming gas turbines in your neighbourhood is "a huge positive". Turbo-charging the climate catastrophe with the CO2 output of entire countries is a "a huge positive". /s
in reply to Neil Brown

Debian was the OS I planned to switch to, in part because I didn't see this coming either.
I probably should have given just how much it's infiltrated everything else and my cynicism over it.

I agree with what Elementary said: "you still have the problem of major underlying infrastructure including the Linux kernel itself. I think we have to take a harm reduction approach right now and do our best with what we have control over"

I don't have control over much, but I can change my OS.

Neil Brown reshared this.

in reply to tiddy roosevelt

@babe there was an abortive attempt to introduce a GR explicitly permitting LLM use a few months ago by obe of the former project leaders - this time the trigger was an explicitly anti LLM GR, but that initial attempt is basically what option B was on the ballot.

I started being worried when seeing some other names I recognise (including at least one other former DPL) seconding it (and seconding option E that won which is arguably worse)

But I was still caught by surprise, I figured worst case option B carries the day acknowledging all the negative impacts... I guess people who really want to use AI find being reminded of what they are doing uncomfortable

in reply to Neil Brown

I think "environmental harm" needs to come with some sort of disclaimer.

In the US, yeah, I have no idea how the way they're building datacenters there is legal.

Here in Sweden they run on 100% renewable energy and don't use up water.

I feel the whole environmental debate around LLMs has centered on what happens in the US, with very little actual data shown.

ourworldindata.org/how-much-energy-do-data-centers-and-artificial-intelligence-use

in reply to Troed Sångberg

@troed Gut feeling / educated guess? Swedish usage is less than 1 % of US usage and US practices are more widely spread in the world due to the sheer monetary pressure and influence.

I'm fairly certain Sweden is the unicorn in this, working enforcement is still quite rare in the rest of the world, even if regulations exist. EU countries are rich and can afford it, most countries focus on primary needs like health and education.

China seems all in for the surveillance value, no limits.

in reply to CohenTheBlue

@cohentheblue

"China seems all in for the surveillance value, no limits."

China release their LLMs as open weights, meaning others (like Mistral in France) can run them in their own datacenters.

For some reason (and I have a guess) China is spending a lot of money making sure the world has access to extremely capable Frontier level AI at only the cost of hosting them.

I run such a model myself, on my own GPU in my dev workstation. The energy usage is thus the same as when playing a game.

@neil

in reply to Neil Brown

I am not overly surprised by this, it is a pragmatic rather than political approach. Banning LLM use is a lot harder (impossible) to police than the whole Debian "free software" stance.

It is a little disappointing that Debian of all distros couldn't have chosen to take a moral high ground on this though, as futile as it may be.

LLM/GenAI is super accessible, it has replaced search for many developers, because search is broken, the next step to having it generate code is a small shift from copy-pasting the odd line from docs or websites. So much coding is gluing together boilerplate and examples anyway. They could have "banned" GenAI use in Debian code, but this would never have stopped GenAI use in Debian code.

The current environmental and economic issues of LLM/GenAI are worth making a stand about though.

As a fairly pragmatic Debian user of some 30+ years I am conflicted. Though as a developer, for work purposes, I do make use of LLM tech — so I am myself tainted.

in reply to Yvan

hm, I should have said near-30 yers lol. My first Debian install was 1998! So more like 28 years. But... details. It has been a long old time, albeit with a slight Ubuntu dalliance on desktop for a bit.

The developer perspective is the hard one right now. LLM generated code is entering the "corpus" of knowledge whether we like that or not, whether we use the tools or not. Probably a majority of developers in the world are using it, with those of us uncomfortable with it being a small niche, and those who take the harder stance of not touching it being an even tinier niche.

It is simply no longer possible to guarantee anything is free of LLM content/influence unless you have 100% written it yourself with no non-textbook/fundamental reference material. (And given time even the books and core references will be tainted in many cases.)

There is no way to tag or otherwise identify a line of code as LLM tainted.

in reply to Neil Brown
I can't actually recommend that you wade in very far, but if you do, you will see that many developers voted for options that focused on environmental (and other harms) of AI. It just happens that the winning option chose to pretend those harms don't exist. It's like "shitty elected leader $Y of country $X"; as a non-$Y supporter you have to live not only with a shitty leader, but also the reputational damage to being from country $X.
in reply to Neil Brown
The environmental concerns are tricky; I'd condemn the crazy huge datacentre buildouts - but locally run AIs aren't that bad - and most people don't know the huge power usage of CI systems that we've depended on for decades; there's also lots of different types of AI usage - the 'agent' stuff is very heavy compute, reviewing code or small rework isn't that bad.
in reply to Neil Brown
I need to read it. On point 2, I think it's going to be more or less impossible to pursue claims over time, I can't envisage a scenario where an organisation can sue on the basis an AI was used and that AI copied their work, when they're almost certainly using AI themselves! On point 3, I think it's a massive missed opportunity to not put some eco requirements into policy - it would be hard to enforce, but it would draw a line and would make people think at least.
in reply to Greg Harvey 🌍

Somewhat related: I had to write @codeenigma's AI policy this year, on consultation with colleagues and peers of course, which was interesting.

It ended up being "unless there's a strong business case, don't" i.e. you need to be able to prove "AI will definitely make this better". Coupled with "here's a list of permitted AI services and models, you may not use any others". The second part attempts to minimise environmental impact, we added environmental credentials to supplier selection.

in reply to Greg Harvey 🌍
@greg_harvey this is why declaration style policies are not good. There should be practical consensus. Imho local LLMs are less issue. Commercial LLMs are no go for me due of copyright sources. People should be responsible and responding on any inquiries about how code was made.
It will make maintaining harder, but expecting magical wand that doesn't include any LLM - even local model run on correctly owned code base - is a lot of understandbly but hot air and not practical.
in reply to Neil Brown

I think I am a bit less surprised - I have seen a lot of pro-AI posts on Debian lists recently (not subscribed to, just other people have highlighted). I sadly think it's inevitable that genAI will make its way into pretty much every Linux distro that is widely used, in the same way as systemd did.

Having been an environmental campaigner in the past, I've also seen how easy it is for people to think 'well my emissions don't matter' (for whatever reason, e.g. China burns lots of coal).

in reply to Neil Brown

Another thing that isn’t discussed. Open source relying on a closed (not just source, models and every other way) and paid system makes it no longer open source.

The idea to be able to have a whole system, a whole ecosystem, of fully free software is a key concept that is now broken more and more. Imagine if open source ran on closed sourced compilers.

Open source is, imho, falling apart in one more way because of this.

in reply to Neil Brown
In my experience software devs (and folks in tech in general) are shit at ethics or thinking through social impacts. Hell, even the guy at work whose job is accessibility, says they are an environmentalist and solarpunk, is all-in on LLM bullshit. Some folks are oblivious fucking morons and they are calling the shots and steering technologies with a huge blast radius.
in reply to Neil Brown
For a distro that consistently selects stable software, allowing AI in, this clearly unstable and buggy tech, seems clearly out of place. Not to mention the moral pit it's found in, Debian stands for more than just stability, there are principles that guide its development as well, and these are also not met by allowing AI use. And we can do away with the "responsible" subjective crutch. Everyone is going to think their own selfish use "responsible".
Esta entrada fue editada (hoy, 18:05)
in reply to Neil Brown

You are aware, that due to the fact "genAI" for code exists for lots of months already, there is practically 0 chance you can find any distro free of that ?

And besides, Linus was OK that the maintainers use genAI code as long its still being reviewed by humans. This would mean if leaving Debian due to genAI code the consequence would mean to also stop using Linux for same reason.

in reply to Neil Brown

I suggest wait a bit more with your decision.

Distros and also the three big BSDs are using many identical programs.

Just think about maybe Wayland having genAI code inside, then you would need to reduce anything to a terminal keeping that strict.

I have no proof or such, but I really suppose that when using any modern GUI , no matter which OS , there is already genAI code inside.

in reply to Neil Brown

Just found this. Seems even FreeBSD "uses" AI itself (not related to genAI code )

freebsdfoundation.org/blog/freebsd-ai-assisted-vulnerability-discovery-project-launch/

in reply to Neil Brown

The ban AI because of environmental harms was the most popular of the anti AI positions.
vote.debian.org/~secretary/gr_llm/

I'm wondering how many of the pro-AI devs are seeing the user backlash?

As for alternatives, haiku has a ban looks like it can boot on real hardware right now if you can put up with retro nextstep/afterstep UI conventions.

Redox OS has much less hardware support and ported software but microkernels are cool.

I haven't figured out how much hardware hurd supports, but it's been a target for guix and debian for a while so has a significant amount of software available.

Haiku and Redox have anti AI positions, Hurd is in the FSF hasn't announced a policy yet problem.