The Fedora council wish to officially propose a policy on AI-assisted contributions in Fedora. This policy was drafted from the initial WIP that was posted to discussion.fedoraproject.org and incorporating discussions from the wider community into something that can be
We will use the Policy Change Policy to either accept or reject this proposal after a period of two weeks for community feedback, and this ticket will serve as where the official vote will be recorded.
The proposal can be read on the community blog and on discussion.fedoraproject.org. Feedback is welcome on the discussion post during the two week period from today.
I've been working with the feedback in the discussion thread, with some revisions along the way, which I posted to thread for further feedback. Based on that process, this is the current draft:
Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for their contributions.
The key words “MUST NOT”, and “SHOULD”in this document are to be interpreted as described in RFC 2119.
Transparency: To foster collaboration and help the community develop best practices, contributors SHOULD disclose the use of generative AI tools to create or substantively modify contributions. This is a strong recommendation in line with RFC 2119. Routine use of assistive tools for correcting grammar and spelling, or for clarifying language, does not require disclosure. Disclosure should be made where authorship is normally indicated. For contributions tracked in git, the recommended method is an Assisted-by: commit message trailer. For other contributions, disclosure may include document preambles, design file metadata, or translation notes.
Assisted-by:
Contribution & Community Evaluation: AI tools may be used to assist human reviewers by providing analysis and suggestions. However, an AI MUST NOT be the sole or final arbiter in making a substantive or subjective judgment on a contribution, nor may it be used to evaluate a person’s standing within the community (e.g., for funding, leadership roles, or Code of Conduct matters). This does not prohibit the use of automated tooling for objective technical validation, such as CI/CD pipelines, automated testing, or spam filtering. The final accountability for accepting a contribution, even if implemented by an automated system, always rests with the human contributor who authorizes the action.
Additional edits from @bookwar from this discussion thread.
You MAY use AI assistance for contributing to Fedora, as long as you follow the principles described below.
Accountability: You MUST take the responsibility for your contribution: Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for their contributions.
Transparency: You MUST disclose the use of AI tools when the significant part of the contribution is taken from a tool without changes. You SHOULD disclose the other uses of AI tools, where it might be useful. Routine use of assistive tools for correcting grammar and spelling, or for clarifying language, does not require disclosure.
Information about the use of AI tools will help us evaluate their impact, build new best practices and adjust existing processes.
Disclosures are made where authorship is normally indicated. For contributions tracked in git, the recommended method is an Assisted-by: commit message trailer. For other contributions, disclosure may include document preambles, design file metadata, or translation notes.
Examples: Assisted-by: generic LLM chatbot Assisted-by: ChatGPTv5
Contribution & Community Evaluation: AI tools may be used to assist human reviewers by providing analysis and suggestions. You MUST NOT use AI as the sole or final arbiter in making a substantive or subjective judgment on a contribution, nor may it be used to evaluate a person’s standing within the community (e.g., for funding, leadership roles, or Code of Conduct matters). This does not prohibit the use of automated tooling for objective technical validation, such as CI/CD pipelines, automated testing, or spam filtering. The final accountability for accepting a contribution, even if implemented by an automated system, always rests with the human contributor who authorizes the action.
Large scale initiatives: The policy doesn’t cover the large scale initiatives which may significantly change the ways the project operates or lead to exponential growth in contributions in some parts of the project. Such initiatives need to be discussed separately with the Fedora Council.
Concerns about possible policy violations should be reported via private tickets to Fedora Council(link).
The key words “MAY”, “MUST”, “MUST NOT”, and “SHOULD” in this document are to be interpreted as described in RFC 2119.
+1
Thanks again @jasonbrooks for driving this, and @bookwar for the thoughtful edits.
Per the Council meeting last week, we agreed to target a ticket vote by Wednesday, 15 October, but I suspect we need meeting time on Wednesday, 22 October to allow all Council members the time to read and digest this.
As a further reminder to all, avoid non-voting discussion on this ticket and share any input on the policy in the public Fedora Discussion topic.
we agreed to target a ticket vote by Wednesday, 15 October,
We have not explicitly agreed to anything but postponing the vote.
@jspaleta @jflory7 @bookwar @jasonbrooks @jonatoni @churchyard @dcantrel @t0xic0der we are in the 4th week of the Policy Change Process for the proposed AI policy, and nearly a week since we clarified what version of the policy we are discussing. As we have a council meeting on Wednesday, I would ask all council members to please vote in the pagure ticket before the meeting on the current policy proposed to either accept or reject it. We require a Full Consensus for this policy to pass, and I would like us to use FESCo's method of voting, with a minor tweak: - +1 is agreement - we will not use a 0 vote - If you are -1 to the current policy proposed, please vote that way. This will automatically trigger that the policy be discussed in the meeting on Wednesday, and the person/people who are -1 MUST be present to provide their reasoning. - If there are any -1 votes, we ALL will need to work together to figure out a path forward for full consensus on a policy on Wednesdays meeting.
This instruction has been posted n the #fedora-council matrix room, discussion thread and email announcement too for transparency on where we are in the process for voting.
Additional edits from @bookwar from this discussion thread. Fedora AI-Assisted Contributions Policy You MAY use AI assistance for contributing to Fedora, as long as you follow the principles described below. Accountability: You MUST take the responsibility for your contribution: Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for their contributions. Transparency: You MUST disclose the use of AI tools when the significant part of the contribution is taken from a tool without changes. You SHOULD disclose the other uses of AI tools, where it might be useful. Routine use of assistive tools for correcting grammar and spelling, or for clarifying language, does not require disclosure. Information about the use of AI tools will help us evaluate their impact, build new best practices and adjust existing processes. Disclosures are made where authorship is normally indicated. For contributions tracked in git, the recommended method is an Assisted-by: commit message trailer. For other contributions, disclosure may include document preambles, design file metadata, or translation notes. Examples: Assisted-by: generic LLM chatbot Assisted-by: ChatGPTv5 Contribution & Community Evaluation: AI tools may be used to assist human reviewers by providing analysis and suggestions. You MUST NOT use AI as the sole or final arbiter in making a substantive or subjective judgment on a contribution, nor may it be used to evaluate a person’s standing within the community (e.g., for funding, leadership roles, or Code of Conduct matters). This does not prohibit the use of automated tooling for objective technical validation, such as CI/CD pipelines, automated testing, or spam filtering. The final accountability for accepting a contribution, even if implemented by an automated system, always rests with the human contributor who authorizes the action. Large scale initiatives: The policy doesn’t cover the large scale initiatives which may significantly change the ways the project operates or lead to exponential growth in contributions in some parts of the project. Such initiatives need to be discussed separately with the Fedora Council. Concerns about possible policy violations should be reported via private tickets to Fedora Council(link). The key words “MAY”, “MUST”, “MUST NOT”, and “SHOULD” in this document are to be interpreted as described in RFC 2119.
I am +1 to approving this version
For substantially unmodified AI generated changes, Generated-by: would be more appropriate.
Generated-by:
I am -1. See below.
The last sentence can be read in an ambiguous way. "Their" can be interpreted in a way that excludes content from a generative AI system, which I believe we are trying to assert that a contributor is responsible for anything they contribute--either created by themselves or obtained from a generative AI system.
Put another way, "their" can be read to be referring to the individual's own contributions or pointing to the generative AI system's work that the contributor is taking and then contributing. Something like "The contributor is always the author and is fully accountable for the entirety of their contributions, both original works and those assisted by generative AI." or something like that.
If I have misinterpreted the Accountability section, then that further reiterates the ambiguity of it...at least from my point of view.
@jspaleta @jflory7 @bookwar @jasonbrooks @jonatoni @churchyard @dcantrel @t0xic0der we are in the 4th week of the Policy Change Process for the proposed AI policy, and nearly a week since we clarified what version of the policy we are discussing.
Just a reminder that my FAS account is @dcantrell. If you use @dcantrel, I won't see it. It used to be @dcantrel, but that one is not active and should really be removed. Years ago I was able to get it changed to @dcantrell which is what I've been using ever since.
I am -1. See below. Accountability: You MUST take the responsibility for your contribution: Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for their contributions. The last sentence can be read in an ambiguous way. "Their" can be interpreted in a way that excludes content from a generative AI system, which I believe we are trying to assert that a contributor is responsible for anything they contribute--either created by themselves or obtained from a generative AI system. Put another way, "their" can be read to be referring to the individual's own contributions or pointing to the generative AI system's work that the contributor is taking and then contributing. Something like "The contributor is always the author and is fully accountable for the entirety of their contributions, both original works and those assisted by generative AI." or something like that. If I have misinterpreted the Accountability section, then that further reiterates the ambiguity of it...at least from my point of view.
The sense you're calling for, @dcantrell , is what we do want, and that's how I read the current text, but we can make it more explicit. What about just "fully accountable for the entirety of these contributions." The text already calls out "whether from a human author or assisted by" in the previous sentence, the "these" refers more directly to that previous sentence.
I'm +1 to this version
I am -1. See below. Accountability: You MUST take the responsibility for your contribution: Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for their contributions. The last sentence can be read in an ambiguous way. "Their" can be interpreted in a way that excludes content from a generative AI system, which I believe we are trying to assert that a contributor is responsible for anything they contribute--either created by themselves or obtained from a generative AI system. Put another way, "their" can be read to be referring to the individual's own contributions or pointing to the generative AI system's work that the contributor is taking and then contributing. Something like "The contributor is always the author and is fully accountable for the entirety of their contributions, both original works and those assisted by generative AI." or something like that. If I have misinterpreted the Accountability section, then that further reiterates the ambiguity of it...at least from my point of view. The sense you're calling for, @dcantrell , is what we do want, and that's how I read the current text, but we can make it more explicit. What about just "fully accountable for the entirety of these contributions." The text already calls out "whether from a human author or assisted by" in the previous sentence, the "these" refers more directly to that previous sentence.
Thanks. I only pointed this out because I did see the previous sentence but then the last sentence was less definitive and left a bit a confusion depending on how you read it. At least to me.
TL;DR, I want the last sentence of that sentence to be the explicit, clear, and non-ambiguous summary of the Accountability section.
@jspaleta @jflory7 @bookwar @jasonbrooks @jonatoni @churchyard @dcantrel @t0xic0der we are in the 4th week of the Policy Change Process for the proposed AI policy, and nearly a week since we clarified what version of the policy we are discussing. Just a reminder that my FAS account is @dcantrell. If you use @dcantrel, I won't see it. It used to be @dcantrel, but that one is not active and should really be removed. Years ago I was able to get it changed to @dcantrell which is what I've been using ever since.
Ooops sorry @dcantrell! I accidentally chose the evil twin :laughing:
@dcantrell with that revision to the last sentence, would that make you +1 to this policy version, or are there other concerns you want to talk through that are keeping you at -1?
Gentle reminder for @jspaleta and @bookwar for their votes please.
As @t0xic0der is new to the council in this context (they have only been added to the council as a mindshare rep formally this week) you may abstain from this vote if you'd prefer.
Likewise @ryanlerch and @jasonbrooks , as initiative leads on the council, feel free to abstain from voting on project-wide decisions if you are not comfortable doing so. That expectation is a bit unfair to hold initiative leads to.
@jspaleta @jflory7 @bookwar @jasonbrooks @jonatoni @churchyard @dcantrel @t0xic0der we are in the 4th week of the Policy Change Process for the proposed AI policy, and nearly a week since we clarified what version of the policy we are discussing. Just a reminder that my FAS account is @dcantrell. If you use @dcantrel, I won't see it. It used to be @dcantrel, but that one is not active and should really be removed. Years ago I was able to get it changed to @dcantrell which is what I've been using ever since. Ooops sorry @dcantrell! I accidentally chose the evil twin :laughing:
How do you know I'm not the evil one? :smirk:
:laughing: :eyes:
I do have a question about the Transparency section. In Accountability we are requiring all contributors to take full responsibility for everything they contribute, be it their own work or AI-assisted work. But then in Transparency we're asking them to label the things AI did or assisted with. Why? To me that's in conflict with Accountability in a few ways. First, it's basically saying we don't fully trust contributors. Second, it's giving contributors a way out of full responsibility for contributions. I don't understand why we want to care about that if we also want contributors to have full responsibility for contributions.
Regarding voting on the proposal... I do not like that we are insisting on a unanimous vote here. I think we should be allowed to vote for or against or abstain, like anything else. Otherwise this just feels like theater as we strongarm everyone in to ultimately voting for the proposal.
I have other issues with the existence of the policy and I don't think any revisions will be able to do anything about it. I have strong concerns regarding creator rights and licensing that is still largely an unknown in the world of generative AI systems. I feel strongly about that because I have built my career on open source software and want the terms of the licenses I have used for projects respected and followed. The generative systems I see today are not making the same effort and that worries me for the future of open source in general. If we all kick the can down the road and say we'll figure it out later, then it may be too late.
Regarding licensing and the scope of the Fedora project... what do we do about projects who have set terms on their code that they will not accept AI-based or AI-assisted contributions, so we carry a patch in Fedora? We're having to violate our position of upstream first in that case. Or projects that set terms saying our code cannot be used with AI-assisted code? These may seem far-fetched, but it's not out of the realm of possibilities.
We're not strictly a home for upstream projects to exist, but we have some. Despite that, Fedora's decisions and policies do lead the community and upstream projects pay attention to our decisions because of their interest in being part of Fedora.
At this point in time I am not sure that Fedora can really have an effective AI-use policy that covers these unknowns. But I understand the desire to write and publish one now. But this entire exercise feels like more of a game around a foregone conclusion.
I'm obviously +1, but my initiative ran its course, so I think I'm not technically on the council any more?
@amoloney We're not asking people to not abstain, right? More that we begin hashing out -1 votes ahead of time?
contributors to take full responsibility for everything they contribute, be it their own work or AI-assisted work. But then in Transparency we're asking them to label the things AI did or assisted with. Why? To me that's in conflict with Accountability in a few ways. First, it's basically saying we don't fully trust contributors. Second, it's giving contributors a way out of full responsibility for contributions. I don't understand why we want to care about that if we also want contributors to have full responsibility for contributions.
On this part, @dcantrell, the text explains the thinking, "Information about the use of AI tools will help us evaluate their impact, build new best practices and adjust existing processes." Being clear about what we're using is something that was important to the community during the time we discussed this. Maybe it'll lead some to evaluate the contributions differently, maybe it'll lead others to share their own tools and techniques. We're getting into something new here, and we want to take it on together.
@dcantrell, Do we not already have packaging policy that puts an emphasis on minimizing divergence with upstream projects? I would expect contributors at the Fedora project who are patching upstream projects, that have a more restrictive contribution policy, to use reasonable judgement here and to follow upstream project policy and to avoid a situation where patches are explicitly un-upstreamable. Nothing in this policy overrides a principled use of an upstream first approach. If anything, this policy ensures Fedora package mantainers can continue to work within the bounds of a diverse set of upstream project policies, making it possible to both push patches upstream and cherry-pick from upstream as needed on an upstream project by project basis.
In the same way I would expect patches to be licensed in a way that was compatible with upstream licensing. Technically its possible to mix MIT licensed upstream with a BSD patch, but why would any Fedora maintainer choose to license a patch that way and make that patch unupstreamable for that specific project? Upstream first policy requires Fedora maintainers to make downstream reasonable decisions that keep their patches aligned with upstream policy, this policy doesn't change that.
This is where the transparency clause in this policy will provide some long term benefit, If we find that Fedora Project contributors are building up an increasingly divergent set of downstream patches because of AI use, at a faster rate than other reasons, we can work with the packaging committee to be more explicit about a downstream patch must be in a form that is upstreamable, and be able to justify when it is not as an exceptional process. In the meantime I would expect that package maintainers will use reasonable judgement and self-interest to avoid increasing their own maintenance burden by unnecessarily creating patches in a way that can't be upstreamed.
I'm +1 on this version.
Regarding voting on the proposal... I do not like that we are insisting on a unanimous vote here. I think we should be allowed to vote for or against or abstain, like anything else. Otherwise this just feels like theater as we strongarm everyone in to ultimately voting for the proposal. @amoloney We're not asking people to not abstain, right? More that we begin hashing out -1 votes ahead of time?
On this part - asking to forgoe 0 votes, I'm wrong to insist that. We actually do have it defined in the charter that full consensus is 3 +1 votes. So on reflection, it is acceptable for a council member to vote 0 with the meaning as being something like 'I don't like this, but I'll stand aside'. But all council members should vote in some way. With my personal opinion being initiative leads should have the option to abstain.
Sorry, forgot to formally vote: +1 for me.
Including the edit I mentioned in the meeting, we'd have:
Fedora AI-Assisted Contributions Policy You MAY use AI assistance for contributing to Fedora, as long as you follow the principles described below.
Accountability: You MUST take the responsibility for your contribution: Contributing to Fedora means vouching for the quality, license compliance, and utility of your submission. All contributions, whether from a human author or assisted by large language models (LLMs) or other generative AI tools, must meet the project’s standards for inclusion. The contributor is always the author and is fully accountable for the entirety of these contributions.
Regarding licensing and the scope of the Fedora project... what do we do about projects who have set terms on their code that they will not accept AI-based or AI-assisted contributions, so we carry a patch in Fedora? We're having to violate our position of upstream first in that case. Or projects that set terms saying our code cannot be used with AI-assisted code? These may seem far-fetched, but it's not out of the realm of possibilities. @dcantrell, Do we not already have packaging policy that puts an emphasis on minimizing divergence with upstream projects? I would expect contributors at the Fedora project who are patching upstream projects, that have a more restrictive contribution policy, to use reasonable judgement here and to follow upstream project policy and to avoid a situation where patches are explicitly un-upstreamable. Nothing in this policy overrides a principled use of an upstream first approach. If anything, this policy ensures Fedora package mantainers can continue to work within the bounds of a diverse set of upstream project policies, making it possible to both push patches upstream and cherry-pick from upstream as needed on an upstream project by project basis.
The concern I have is that by introducing this policy we run the risk of putting maintainers in a difficult position where patches coming in via Fedora users or via bug reports through Fedora but ultimately pushed upstream can run the risk of not being accepted upstream if AI-assistance becomes large enough in the downstream work and upstream has an no-AI policy.
I don't want us to find ourselves in a situation where we are forced to either ask maintainers to fork projects or undo whatever AI policy we agree on. That sounds extreme, but it's meant as a hypothetical. Since all of these projects in the open want to work together, we should be aware of what upstreams are doing and make sure we don't enact a policy that forbids contribution from us or use of future releases of an upstream project.
My concern around licensing is more around AI-assisted contributions using or potentially using code snippets taken from existing projects, but those AI systems not telling the user where they came from. If these AI systems are capable of generating code based on what it's learned from stuff it found online, then why can't it also know what the license of that code is (and ownership!) and tell the user? "Write me a function that computes the factorial of a number." and it gives you code but then says "oh and I found that here and it was written by this person and is licensed under ____". Maybe this already exists, but if AI-assistance is helping with code it can also help educate people about the licenses.
I see what you're saying, but I don't agree here. I don't think the Transparency section will help with that, but I could be entirely wrong. Hopefully I am. Thank you for clarifying it for me.
Thank you everyone for the feedback and responding to my comments and concerns.
With the latest revised revision draft, you can count me as a +1
+1 to the latest revised draft.
+1 as well
+1 to the latest revised draft
See Fedora-Council/council-docs#268.
Metadata Update from @jflory7: - Issue assigned to jasonbrooks
The AI-Assisted Contributions Policy is now published as an official Fedora policy. See link below. I am closing this ticket as approved.
approved
https://docs.fedoraproject.org/en-US/council/policy/ai-contribution-policy/
Metadata Update from @jflory7: - Issue close_status updated to: approved - Issue status updated to: Closed (was: Open)