When the contribution is free but the reviewer is not: AI hits FOSS and standards culture
An Emacs LLM-agent package, a wave of AI Internet-Drafts, and a Claude-led break of a NIST PQC candidate force the same question: is machine output legitimate work or noise that burns scarce trust.
The fight is no longer whether generative models can write code, drafts, or cryptanalysis. It is whether communities built on human review can absorb that output without abandoning the philosophies, bandwidth, and trust that make the work legitimate. Three threads that look unrelated (a NonGNU ELPA packaging debate on emacs-devel, a surge of independent IETF Internet-Drafts, and an AI-assisted key-recovery result against the HAWK post-quantum signature candidate) are the same collision playing out in different rooms.
On emacs-devel the spark was concrete. Thanos Apollo offered hermes, an Emacs front end for Hermes Agent: EWOC dashboard and chat, streamed Markdown and diffs, approval and secret prompts, session and model management, browsers for tasks, cron, MCP servers, skills, and subagents. The technical pitch was ordinary package hygiene. The reaction was not. Richard Stallman treated the submission as a freedom question first: what does shipping hermes.el actually lead users to run and depend on. After chasing documentation about local models and provider catalogs, he drew a hard line. "We must not guide/lead users to install the Hermes app, so we must not guide/lead them to install hermes.el."
That line split into several arguments at once. One strand was factual and terminological. Stallman read "pricing models" language as commercial entanglement with nonfree software and payment sites. Jean Louis pushed back that "priced against your machine" was about GPU and RAM fit, not money, and tried to keep the GCS reading precise. Eli Zaretskii pressed for exact page text and a clean fact pattern: hermes.el and the agent as free programs, no nonfree links in the obvious places, communication with a free agent. Another strand was the deeper GNU habit of looking past the package binary to what it normalizes. Jean Louis invoked the long-standing mplayer analogy and the SaaSS concern: even free software can be judged by what it strongly encourages. Hermes Agent, in his telling, surfaces roughly thirty providers, nearly all service-as-a-software-substitute, with a recommended fast path pre-selected. Eli tried to separate issues and keep the list from flooding while he worked the question with Stallman. The packaging fight was never only about one .el file. It was about whether an LLM agent front end is a neutral tool or a guided on-ramp into a stack the project refuses to bless.
A third strand was social and almost as sharp. Stallman described the submitter's answers as starting to address the questions yet remaining "fragmentary and incomplete, partly because they were terse," and said assembling the full dependency picture had become "a daunting task of study and cross-correlation." Jacob S. Gordon sympathized with the intensity of first-of-its-kind scrutiny, then drew a different boundary: "I feel like a line was crossed in the latest LLM-automated exchange, and that our community would be worse off if that were normalized." His mail footer asked not to receive messages composed with LLMs. On a list that still argues about HTML mail, bot-shaped replies landed as a norms violation, not a convenience.
The same scarcity problem shows up with less philosophy and more volume at the IETF. Independent Internet-Draft traffic has spiked hard enough that Ross Finlayson opened with "this is getting out of hand" and, after a joke about posting bonds, said the community needs to treat the pattern "as a problem akin to spam." Split announce lists, rate limits, detectors, and web-of-trust shepherds are all on the table. Theodore Ts'o pointed at watermarking work and public detectors as tools that might help for some model families. Andrew Yourtchenko reported that among drafts adopted in a year window, only a small set had entire author lists with no prior RFC or working-group draft footprint, and floated shaping -00 limits around a free first shot plus a shepherd from people already in the work.
Lars Eggert refused the fantasy of putting the genie back. "I believe the issue of fully or partially AI-generated IETF contributions is here to stay." Used carefully, models might accelerate standards work; used carelessly, they recreate the open-source pull-request pattern he named without euphemism: generation is cheap, "the cost is shifting to core review, which is not (yet?) similarly cheaply done." His personal adaptation is blunt. He expects to disregard new work from people without history unless someone he trusts engages or the topic is central to him. Carsten Bormann answered the obvious failure mode (genuine newcomers drowned in slop) with attention infrastructure: multi-level commendations, viewer-private weighted scores from past authors and leadership, freshness, sorting that is subjective on purpose. Carlos Martinez-Cagnazzo added the uncomfortable mirror: one defense against AI slop may be AI tuned to IETF style, attaching metrics to each -00. Licensing cans of worms (who can grant the required rights on machine text) sit mostly unopened while the operational question dominates: how does a volunteer standards body stay open when first drafts multiply faster than careful readers.
Cryptography supplies the case where machine output is not dismissed as noise. On the NIST PQC forum, Steve Weis announced an improved HAWK-n key-recovery attack reducing to SVP in dimension n/2 + 1, with gate-count costs dropping HAWK-512 from 2^150 to 2^108 and HAWK-1024 from 2^288 to 2^182, plus a practical end-to-end recovery of a HAWK-256 secret in hours on one server. Daniel Apon said it checked out independently. The HAWK team helped verify. The attribution line was explicit: "this was found by Claude, with minimal technical guidance from people." Adjacent threads about other schemes, deployment without waiting for final standards, and hybrid designs continued in the ordinary specialist register. Here the model is framed as a research amplifier whose result still has to survive human verification, parameter consequences, and the brutal economy of which candidates remain credible.
Thread the three together and the through-line is review asymmetry. Emacs debates whether an agent front end is contribution or a freedom hazard and whether LLM-shaped mail is speech the project can tolerate. The IETF debates whether AI drafts are participation growth or a DDoS on attention, and whether the fix is technical filters, social trust graphs, or both. The PQC process shows a path where AI-origin work is admitted only because humans reproduced it, bounded it (no claimed impact on Falcon or ML-DSA in the announcement), and accepted the security fallout. In every venue the scarce resource is the same: people who can tell signal from fluent emptiness, and institutions whose legitimacy rests on that telling.
Nothing is settled. NonGNU and emacs-devel still have to decide what hermes.el leads to under GNU rules, and whether process cruelty or bot etiquette becomes the lasting precedent. The IETF still has to choose mitigations that slow junk without freezing out the next outsider with a real idea, while IP and training provenance questions wait. NIST's signature round absorbs a candidate weakened by an AI-assisted lattice insight, which proves usefulness and raises the bar for every remaining design. The unresolved tension is simple and structural. Communities that prize free contribution are being offered infinite free text. They have not yet agreed when that text counts as work, when it counts as spam, and who pays the review cost either way.