From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 42ABA158041 for ; Tue, 27 Feb 2024 14:45:29 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 8ECD3E2A64; Tue, 27 Feb 2024 14:45:22 +0000 (UTC) Received: from smtp.gentoo.org (woodpecker.gentoo.org [IPv6:2001:470:ea4a:1:5054:ff:fec7:86e4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id 3E4F3E2A1C for ; Tue, 27 Feb 2024 14:45:22 +0000 (UTC) Message-ID: Subject: [gentoo-dev] RFC: banning "AI"-backed (LLM/GPT/whatever) contributions to Gentoo From: =?UTF-8?Q?Micha=C5=82_G=C3=B3rny?= To: gentoo-dev@lists.gentoo.org Date: Tue, 27 Feb 2024 15:45:17 +0100 Organization: Gentoo Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-+liP59yxFyCNQLgiqvxS" User-Agent: Evolution 3.50.4 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@lists.gentoo.org Reply-to: gentoo-dev@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply MIME-Version: 1.0 X-Archives-Salt: 0b32657b-56a4-4ef1-9a4f-aac78421ddec X-Archives-Hash: 56c244acc5570e0769ff89ee50d8184e --=-+liP59yxFyCNQLgiqvxS Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hello, Given the recent spread of the "AI" bubble, I think we really need to look into formally addressing the related concerns. In my opinion, at this point the only reasonable course of action would be to safely ban "AI"-backed contribution entirely. In other words, explicitly forbid people from using ChatGPT, Bard, GitHub Copilot, and so on, to create ebuilds, code, documentation, messages, bug reports and so on for use in Gentoo. Just to be clear, I'm talking about our "original" content. We can't do much about upstream projects using it. Rationale: 1. Copyright concerns. At this point, the copyright situation around generated content is still unclear. What's pretty clear is that pretty much all LLMs are trained on huge corpora of copyrighted material, and all fancy "AI" companies don't give shit about copyright violations. In particular, there's a good risk that these tools would yield stuff we can't legally use. 2. Quality concerns. LLMs are really great at generating plausibly looking bullshit. I suppose they can provide good assistance if you are careful enough, but we can't really rely on all our contributors being aware of the risks. 3. Ethical concerns. As pointed out above, the "AI" corporations don't give shit about copyright, and don't give shit about people. The AI bubble is causing huge energy waste. It is giving a great excuse for layoffs and increasing exploitation of IT workers. It is driving enshittification of the Internet, it is empowering all kinds of spam and scam. Gentoo has always stood out as something different, something that worked for people for whom mainstream distros were lacking. I think adding "made by real people" to the list of our advantages would be a good thing =E2=80=94 but we need to have policies in place, to make sure = shit doesn't flow in. Compare with the shitstorm at: https://github.com/pkgxdev/pantry/issues/5358 --=20 Best regards, Micha=C5=82 G=C3=B3rny --=-+liP59yxFyCNQLgiqvxS Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- iQFGBAABCgAwFiEEx2qEUJQJjSjMiybFY5ra4jKeJA4FAmXd9X0SHG1nb3JueUBn ZW50b28ub3JnAAoJEGOa2uIyniQOvwYH/2uJnHzd6zPYOBnP8DKu7QUnFiIWWwn0 5n2DoKxApzNjcFdHMMcl0PYI76lanT1rdu1tJJm3YdxMTVgy6DrHz3P1DSsiUhne qv199f1AYvgwq08lf5zDr7Xdgh0tDc6/oz/Ou66YQIh9fCFX8W7so5VPIBYtLwIS DKFObvFblXtMMHTFg9pPyQWQE3df14axTbSXo62EhAbwjNKK6lmz2jmIo8+OaCe7 fvLb5hWKtRswpnjljFYbhwP0O3hkOa2uutiPGbx2VbWnWI8Emqxw0RpTNSA612HI GkaJfCCd4q31Z56PTIQ9E4E2XIwQ4rDRGR7C/LpvqnhSU8vYhsqZflY= =Alux -----END PGP SIGNATURE----- --=-+liP59yxFyCNQLgiqvxS--