Kicksecure Policy on Artificial Intelligence (AI)
This navigation is a compilation of Kicksecure project policies.
- Project Policies
- Policy of Website and Chat
- Policy On Nonfreedom Software
- Policy On Artificial Intelligence (AI)
- Wiki Editing Policy
- Wiki Comments Policy
- Source Code Contributor Policy
- Documentation Contributor Policy
- Development Discussion Policy
- Limitations on Free Speech on Website and Chat
- Transparency, Sponsors / Advertisement Policy

Do not post AI-generated content in communications or source code contributions without clearly marking it as AI-generated.
Communications
[edit]- Communications definition: Forum posts, bug reports, feature requests, e-mails, wiki edits, or other forms of communication.
- Marking as AI-generated required: Please DO NOT paste AI-generated content into communications without clearly and unambiguously marking it as AI-generated.
Source Code
[edit]- Marking as AI-generated required: Please DO NOT submit source code changes or pull requests without clearly and unambiguously marking them as AI-generated.
- Human review: All contributions are carefully reviewed by humans to evaluate whether they meet the project's standards.
Author Responsibility
[edit]- Author responsibility: Regardless of how your content was created, you will be considered the fully accountable author of that content, and you are responsible for reviewing and fixing such output before submitting it.
Consequence of Non-Disclosure
[edit]- Non-disclosure may lead to deprioritization: If you do not disclose use of generative AI, and the reviewer has reason to believe that it has been used, your contribution is likely to be deprioritized and may be denied without further review, at the discretion of the reviewer.
- Repeated non-disclosure may lead to a ban: If you intentionally and repeatedly fail to disclose your use of generative AI in a way that is disruptive to the project or its reviewers, you may be banned from further contributions or, in severe cases, from participating in the project altogether.
Rationale
[edit]Generative AI allows potential contributors to generate large amounts of content quickly and at near-zero cost. If these contributions are of high quality, they will be welcome. Unfortunately, however, they are often of low quality, in which case it is easy for even a single GenAI-assisted contributor to overwhelm the entire project’s human review capacity.Qubes OS: Using AI in contributions
/ Qubes forum discussion: Guidance on using AI in contributions
![]()
Examples of Nonsensical AI Generated Posts
[edit]Posts partially or fully written by AI.
- Nonexistent settings: suggesting to enable settings by default, which do not exist

- Self-hosting confusion: post on "self-hosting ChatGPT4"

, which cannot be self-hosted

. "I guess that’s what you get when using ChatGPT to help you work out self-hosting ChatGPT costs."

- Screenshot example: https://daniel.haxx.se/media/curl-github-issue-15736.png

- Blog post example: https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/

- Related report: https://hackerone.com/reports/2199174

- Related report: https://hackerone.com/reports/2199174
- Spam pull requests: https://navendu.me/posts/ai-generated-spam-prs/

- Pull request example:
- Pull request example: https://github.com/Kicksecure/tor-control-panel/pull/1

- https://forums.whonix.org/t/fix-anon-connection-wizard-validation-logic-for-webtunnel-bridges-regex-parsing-error/23233

- list of links here: https://github.com/ossf/wg-vulnerability-disclosures/issues/178

Other Projects Policies
[edit]- Debian: Relevant discussions and reporting on AI contribution policy.
- LWN.net report: LWN.net: Debian AI General Resolution withdrawn

- LWN.net report: LWN.net: Debian dismisses AI-contributions policy

- LWN.net report: LWN.net: Debian AI General Resolution withdrawn
- Qubes OS: Qubes OS: Using AI in contributions

- Forum discussion: Qubes forum discussion: Guidance on using AI in contributions

- Forum discussion: Qubes forum discussion: Guidance on using AI in contributions
- Gentoo: https://wiki.gentoo.org/wiki/Project:Council/AI_policy

- QEMU: https://www.qemu.org/docs/master/devel/code-provenance.html#use-of-ai-generated-content

- Linux Foundation: https://www.linuxfoundation.org/legal/generative-ai

- Policy on the use of Large Language Models (LLMs) and AI tooling

- https://codeberg.org/brib/slopfree-software-index

Other Projects Using Artificial Intelligence
[edit]Non-exhaustive list:
- Prominent examples only.
- Linux kernel: Kernel Guidelines for Tool-Generated Content

- systemd [1]
- Tor Project: https://gitlab.torproject.org/tpo/core/tor/-/commit/32be50cdf44e6df5fab57bcb4d931087bb0c8e09

- Linux kernel: Kernel Guidelines for Tool-Generated Content
To specifically address the worries about the effectiveness of llms, I recommend everyone read the AI review comments on e.g. #39010. AI is at the point where it is catching issues that human reviewers would likely miss and allows us to start making progress on reviewing prs that we otherwise would not find time to review (of course a full human review is still required).
For all the other concerns, this is not a battle to fight on the systemd issue tracker. Those considering a new init system because of this will also need to look for a new kernel as Linux itself is accepting AI contributions as well these days (https://docs.kernel.org/process/generated-content.html
).systemd: Disallow usage of generative AI to write code
, Daan De Meyer (@daandemeyer), systemd/mkosi maintainer
![]()
Just to briefly say one thing: it would be dishonest to not accept the fact that Claude code reviews actually got really really good recently. AI code reviews went from 95% slop and 5% ok, to 80% really good, and 20% garbage. It has been finding real CVEs in the past weeks, and it's just too good to ignore now. Whatever you think of AI, if one is honest, then one has to respect those Claude reviews. Without them systemd code quality would be worse, vulnerabilities that exist would not be found, and that's not a good thing for the world. Just denying all this completely would leave people more vulnerable, code quality much worse and I cannot see how anyone would benefit from that. Yes, AI is problematic in many ways, but it's not a binary thing, and I'd rather be in front of the CVE wave crashing in on us, then leaving it all to blackhat hackers to take benefit of.
The world is a complex place. Things are ambivalent.systemd: Disallow usage of generative AI to write code
, Lennart Poettering (@poettering), systemd developer)
![]()
There are projects that track types of use of AI by Open Source projects:
- https://codeberg.org/ethical-foss/open-slopware

- https://codeberg.org/ai-alternatives/llm-afflicted-software

Forum Discussion
[edit]Credits
[edit]- Based in part on: Qubes OS: Using AI in contributions

(related: Qubes forum discussion: Guidance on using AI in contributions

).
Related
[edit]- Wiki page: Artificial Intelligence (AI)
- Related chapter: Utilize Search Engines, Documentation and AI chapter Artificial Intelligence
- ↑
- systemd: Disallow usage of generative AI to write code

(rejected policy suggestion)
- https://github.com/systemd/systemd/commit/744d589632c545e90ae76853abbfbc90cb530e24

- https://github.com/systemd/systemd/blob/main/.github/workflows/claude-review.yml

- https://github.com/systemd/systemd/blob/main/AGENTS.md

- https://codeberg.org/ai-alternatives/llm-afflicted-software/src/branch/main/system-components.yaml

- systemd: Disallow usage of generative AI to write code
We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 14 year success story and maybe DONATE!