Am 21.09.2026 um 15:20 hat Daniel P. Berrangé geschrieben: > On Mon, Sep 21, 2026 at 09:52:48AM +0200, Paolo Bonzini wrote: > > +.. note:: **Use of AI does not remove the need for authors to comply > > + with all other requirements for contribution.** In particular, > > + the ``Signed-off-by`` label in a patch submission is a statement > > + that the author takes responsibility for the entire contents of > > + the patch, certifying that their patch submission is made in > > + accordance with the rules of the :ref:`Developer's Certificate of > > + Origin (DCO) <dco>`. > > + > > + Since a submitter cannot audit LLM output against its training > > + data, the DCO is paired with :ref:`metadata in the commit message > > + <ai-used-for>` about AI-generated parts. The DCO still certifies > > + that the contributor has the legal right to submit code in > > general. > > I'm not a fan of this second paragraph, as that feels like it is undermining > the DCO. That first sentence in particular is somewhat saying that the > contributor does not have to think about plagarism and thed project is ok > with that, and also implying that the DCO doesn't apply to the LLM output. > This is both not OK in its implication of the project accepting some > liability, and then also contradicted by the next sentence. > > IMHO this paragraph should just be removed. The first paragraph clearly > states the DCO applies to the submission as a whole, and leaves all liability > for infringement on the contributor.
I don't think making this the individual contributor's problem is great. It's rather unfriendly towards contributors to expect them to certify something that we all know they can't honestly certify. Our current AI policy was built on the assertion that it's impossible to sign the DCO for AI output, and I think that's still right. A developer can't certify the origin of something when they don't really know where it comes from. If we decide that we don't care as much about the legal risks any more and that we're willing to accept them to some extent, that should be explicitly reflected in the policy. It seems to me that the cleanest way to do it is to exempt correctly advertised (with 'AI-used-for:') AI output from the DCO requirement and instead add to the 'AI-used-for:' definition some relaxed version of it, e.g. "I have reviewed the contribution for potential licensing issues and haven't found a reason to doubt that I have the rights to submit this AI generated content under the open source license indicated in the file". This is something that could realistically be certified by contributors in good faith and also isn't just "anything goes", but of course it still is weaker than the DCO. If we're not willing to take the legal risk from this, we should probably leave the current AI policy unchanged instead of telling contributors that they have to work in a legal grey area. Kevin
