freenode
AnalysisInternet & Protocols

Ban, structure, or disclose: three projects split on AI-generated work

IETF floods, a QEMU policy U-turn, and an ELPA fight with RMS show the same governance crack: whether to forbid generative tools, channel them, or force transparency.

Across standards lists, hypervisor trees, and GNU packaging, the same cheap generation problem has arrived at once. Producing an independent Internet-Draft or a plausible patch series is suddenly inexpensive; reading it is not. IETF participants are calling a spike of independent submissions AI slop and floating detectors, rate limits, and webs of trust. QEMU is preparing to scrap an unenforceable blanket ban for AGENTS.md rules aimed at the tools themselves. An ELPA bid for an LLM-assisted Sapling client has drawn Richard Stallman into a hard line over rejecting generated code. The argument is no longer whether the tools are present. It is whether communities ban them, structure them, or demand disclosure, and those three answers are colliding in public.

The IETF thread opened in alarm. Ross Finlayson wrote that independent draft traffic was "getting out of hand" and should be treated "as a problem akin to spam." His half-serious bond refundable only on working-group adoption was a joke against IETF ethos, but the practical ask was separation: a working-group announce list versus an independent one so people could unsubscribe from the noise. S. Moonesamy supplied a heatmap showing an unusual 2026 jump in -00 submissions and noted that some working-group traffic itself looked AI-shaped, with drafts that appeared because generation "lowered the barrier to write a draft." Stephen Farrell, reading the same curve, ventured a "pandemic of probable crap" in -00 emissions. Andrew Yourtchenko added a sharper adoption filter: of drafts adopted over a year window, only fourteen had author lists entirely new to prior RFCs or working-group work. That statistic pushed his proposal away from a pure numeric throttle toward a web-of-trust shape: one free-hanging -00 per account, then a shepherd drawn from people already in the guides and machinery of participation, with the flag clearing if the Independent Stream Editor later published the work.

Others reached for technical and social filters rather than gates at the door. Theodore Ts'o pointed at regulatory watermarking and vendor detectors (SynthID and similar), useful against some commercial models even if open-weight stacks remain opaque. Lars Eggert argued the deeper point: fully or partially AI-generated contributions are "here to stay," stopgaps will blunt DDoS-like bursts at best, and the real shift matches open source pull requests that are cheap to open while review stays expensive. His personal adaptation was blunt sociology. He would more quickly ignore newcomers unless someone he already trusted engaged, or the topic sat in an area he cared about. Carsten Bormann named the cost of that adaptation: the IETF could become less open, with genuine new voices lost in slop. His counter was attention infrastructure inside the Datatracker: non-Boolean commendations, per-viewer weights built from authorship and leadership history, private document scores that help humans allocate scarce reading time without a single global reputation score.

QEMU reached the same cost curve from the opposite policy extreme. Paolo Bonzini floated an intentional "full U-turn" from a provenance rule that declined anything believed to include or derive from AI-generated content. The old equilibrium, he argued, was a "unanimity trap": every narrow carve-out for tests or comments drew rightful objections, so the only stable point remained a total ban the project could not actually police. Maintainers were already seeing AI-shaped series land, often in apparent good faith, while "don't ask, don't tell" stayed a red flag. Conservancy-style advice not to purge either camp, plus Rust's admission that wide consensus was impossible, pushed the hypothesis elsewhere: treat the problem as maintainer burnout rather than pure copyright theater, and perturb hard with structured permission.

The proposed structure is machine-facing as much as human-facing. An AGENTS.md would state participation rules in concise language models are likelier to honor, insist the human remain in the design loop, and pair with tool-specific stubs so agents surface pre-arrangement duties instead of silently emitting large series. Daniel P. Berrangé framed the prior failure as naivety about a policy page buried in developer docs; without an agents file, neither people nor tools were reliably told the rules. Alistair Francis added the enforcement realism: a blanket ban "just leads people to ignore the ban and use AI anyway and lie about it," whereas limited, declared use may produce honest labeling. Peter Maydell resisted the direction on workload grounds. The project, in his view, is not short of code-writing speed; it is short of review bandwidth, already absorbing automated bug finding and unmaintained surface area. Allowing more generated code "feels bad" if it mainly enlarges the reviewer queue. Bonzini's camp answers that agents reminded every few minutes beat a rule everyone has already learned to route around, and that trust in maintainers still bounds what "cautious experimentation" actually accepts.

The Emacs front is smaller in patch volume and sharper in principle. Swithin Chan sought NonGNU ELPA (and hoped for GNU ELPA) for sl.el, a Magit-inspired interface to Meta's Sapling client, written after burning tokens to cope with slow Git on Windows. The submission dragged generative assistance into packaging politics. Stallman's line on adjacent traffic was careful: maintainers may take bug leads that someone obtained with an LLM if they verify the defect, because "LLMs and humans both make mistakes." On the package itself the pressure ran the other way. After pushback, Chan reported removing a header and wrote, "All errors are solely by mine," an attempt to reassert personal authorship for archive acceptance. That exchange restates the hard-line pole: generated material is not merely noisy or hard to review; for some custodians of free-software distribution it is categorically the wrong kind of contribution unless a human fully owns and stands behind every line.

The through-line is governance under asymmetric cost. IETF energy clusters on triage technology and social proof (watermarks, split announces, shepherds, private commendation weights) because the firehose is public and authorship is lightly gated. QEMU energy clusters on replacing a brittle prohibition with rules the generating agents will read, plus human pre-arrangement for large drops, because the bottleneck is maintainer attention inside a single tree. The ELPA exchange clusters on provenance purity and header honesty, because distribution into the GNU orbit still treats how code was made as a first-class question. None of the three has closed the loop. Detectors miss open-weight text; webs of trust can freeze out outsiders Carsten Bormann wants to save; AGENTS.md depends on tools that obey and contributors who do not strip the instructions; disclosure norms collapse when a ban taught people to lie. What remains unresolved is which scarcity communities optimize for (inbox volume, review hours, or licensing certainty) and whether any single project can pick ban, structure, or disclose without the other two leaking back in through the same cheap generators.