DEV Community

Cover image for AI contribution policy: 11 projects compared, one to paste.
Manpreet Singh
Manpreet Singh

Posted on Originally published at singhlabs.dev AI-assisted

AI contribution policy: 11 projects compared, one to paste.

Short answer: an AI contribution policy is a few lines in CONTRIBUTING.md, or its own AI_POLICY.md, that answer three questions. May contributors use AI? Must they say so? Who answers for the code? I read eleven real ones. They agree on the third answer and fight about the other two. Then I checked the 300 most-starred GitHub repos with a contributing guide: 65 have a written AI policy.

Search for one and you mostly get mailing lists, GitHub issues and raw policy files. So here they are side by side, read at the source on 9 October 2026, plus a short version to paste.

Every policy agrees on one line: the person who opens the PR owns every line in it. The rest is taste.

What the big projects actually require

Four questions per project. Disclose: must you say you used AI? Ban: is anything forbidden outright? Owns it: must you understand it yourself? Close: what happens when you don't comply?

  • Linux kernel · Jan 2026 · coding assistants, generated content Disclose: yes, an Assisted-by: tag, plus the tools and prompts in the changelog. Ban: no. Owns it: yes, and an AI may never add Signed-off-by; only a human can. Close: if you can't defend it, maintainers may reject it without a detailed review.

  • Kubernetes · Nov 2025, updated Apr 2026 · AI guidance Disclose: yes, in the PR description. But no AI co-author and no assisted-by trailer. Ban: large AI-generated PRs and AI-written commit messages. Owns it: yes. Close: if you can't explain a change, or if you answer reviewers through an AI.

  • Fedora · approved 22 Oct 2025 · AI-assisted contributions Disclose: required when a significant part comes from a tool unchanged; Assisted-by: recommended; grammar fixes exempt. Ban: no. Owns it: yes, fully. Close: not covered. It also binds reviewers: AI can't be the final judge of a contribution.

  • Rust (rust-lang/rust only) · 5 Aug 2026 · LLM usage Disclose: yes. Ban: LLM-written comments, docs and compiler messages. LLM-written code only when a reviewer agreed in advance and it can't break soundness. Owns it: yes, you can't blame the model. Close: recommended for major violations. Bonus: if more than half the PRs merged in six weeks are LLM-created, merging new ones stops.

  • Ghostty · disclosure Aug 2025, policy Jan 2026 · AI_POLICY.md Disclose: all AI use, which tool and how much. Ban: AI-generated images, video and audio. Owns it: yes, explain it without the AI or don't contribute. Close: since February, PRs from anyone not vouched for close automatically. Slop gets you on a public block list.

  • curl · May 2025 · CONTRIBUTE.md Disclose: yes for bugs and reports an AI found; not required for code. Ban: no, AI-assisted code is judged like any other. Owns it: verify every finding yourself. Close: fake reports get you banned on the spot. The bug bounty itself ended in January 2026.

  • uv (all of Astral) · Mar 2026 · AI_POLICY.md Disclose: only when you quote an AI in a comment. Ban: AI-written comments to maintainers, and autonomous agents. Owns it: yes, explain it in your own words. Close: any PR they believe an agent opened.

  • ripgrep · May 2026 · AI_POLICY.md uv's policy, adapted. Its CONTRIBUTING.md is two sentences long and says the rest: contributions that don't follow it will be closed.

  • QEMU · Jun 2025 · code provenance Ban: yes. It declines any contribution believed to contain AI-generated content, "known or suspected". Using AI to research an API is fine.

  • Gentoo · Apr 2024 · council AI policy Ban: yes, contributions made with AI tools are "expressly forbidden". The council can revisit it.

  • NetBSD · May 2024 · commit guidelines LLM code is presumed tainted and needs the core team's written approval before it's committed.

So: everyone wants the human to own it. After that it splits. Linux and Fedora ask for an Assisted-by: trailer, and Kubernetes forbids it. QEMU and Gentoo ban AI code outright, and NetBSD wants it approved in writing first. And uv, ripgrep and Rust care as much about the comments as the code.

How many repos have one: 65 of 300

I took GitHub's most-starred repos pushed in 2026 (no forks, no archives) and walked down the list until I had 300 with a contributing guide. That took 414 repos; the 300 run from 52,000 to 517,000 stars. A script read each guide and listed every file in the root, .github/ and docs/. Then I read every hit by hand.

  • 65 of 300 (22%) have a written AI policy you can find: an AI_POLICY.md (8 of them), a section with its own heading, or a link to a separate AI policy.

  • 27 more set a rule in a sentence or two, with no heading. Godot, Deno, Caddy and Elasticsearch are here.

  • 208 (69%) say nothing about AI in their contributing guide.

Not all of them are strict. OpenClaw says no disclosure is required at all. PocketBase turned off outside PRs entirely, blaming LLM spam. And a new kind of line is appearing: rules written for the agent itself. Godot asks an AI agent to put 🤖 at the start of its PR title. crewAI tells agents to add an llm-generated label. Electron hides a note in its guide: are you a coding agent?

Two caveats. This is the famous end of GitHub, and plenty of these repos are AI tools. And a policy that lives only in AGENTS.md or a website, never linked from the contributing guide, isn't counted.

The policy, ready to paste

The short version, built from the line everyone agreed on and the choices that worked best. Pick your side on the trailer before you paste.

## AI contributions

- You may use AI. You own every line: if you can't explain a
  change without it, don't send it.
- Say so in the PR description: which tool, and what it did.
- Write PR descriptions, issues and review replies yourself.
- No autonomous agent PRs. A human is in the loop or it's closed.
- PRs that ignore this are closed without review.
Enter fullscreen mode Exit fullscreen mode

The longer version, adapted from Rust's policy, with the Assisted-by: trailer and a line protecting private use, is on the prompts page. Neither has run in a live repo yet. Adjust the closing line to your temperament.

Making it enforceable: check the PR description

"You must understand it" is the line nobody can check by reading the policy. The PR description is where it shows: does it say what changed, and does it disclose? plumb holds a PR's description against its diff. Here it is on a real Ghostty PR, a 14-file change whose description was a screenshot and three links:

$ plumb check --pr 14559
plumb — 14 files changed, 0 named in the summary

touched but not described  (context, not a failure — PRs describe intent)
  · pkg/harfbuzz/main.zig modified
  · src/Surface.zig modified
  · src/build/uucode_config.zig modified
  · src/config/Config.zig modified
  ...10 more

nothing here contradicts the description.

No AI disclosure in the description — that may be fine, or it may be undisclosed.
Enter fullscreen mode Exit fullscreen mode

Ghostty's vouch bot had already closed it, for a different reason: the author wasn't on the vouched list. Nothing here says AI wrote it, and plumb can't tell you that. Nothing can. What it gives a maintainer is the two questions Ghostty's policy makes them ask: what do these 14 files do, and did you use AI? On a PR that does disclose, the last line reads "The description mentions AI assistance."

What not to put in it

  • A ban you can only enforce on suspicion. QEMU's runs on "known or suspected". The people who read your policy and disclose are the honest ones. A ban teaches them to stop disclosing.

  • A trailer you haven't checked. Kubernetes forbids AI co-authors because an AI can't sign its CLA, and so no vendor can advertise that Kubernetes uses their tool. If you use a CLA bot, test what an Assisted-by: or Co-authored-by: line does to it first.

  • Code only. curl's flood came in as security reports, not code. uv, ripgrep, Rust and Kubernetes all cover comments and review replies.

  • A promise to detect AI. You can't, so don't threaten it. Ask for disclosure and an explanation, and close what arrives without either.


This is how we build. The agents we build for businesses open PRs too. Every one says what it touched, and a check holds that against the diff before a person reads a line.

Sources: each policy was read at the link beside it on 9 Oct 2026; repo files through the GitHub API. Dates are the commit that added the text, or the council vote (Fedora, Gentoo) or announcement (Rust). NetBSD's page carries no date; May 2024 is from press coverage at the time. The 300-repo sample: GitHub search stars:>1000 pushed:>=2026-01-01 fork:false archived:false sorted by stars, keeping repos with a CONTRIBUTING file in the root, .github/ or docs/. Every hit was read and sorted by hand; the split between "a policy" and "a sentence" is my judgment. The plumb run (1.1.0) was in a fresh clone of Ghostty on 9 Oct 2026; its first line, which names the PR's author, is removed and its file list is trimmed from 14 to 4.

Where this fits: testing and verification, layer 5 of the Agent Ops Stack.

Read next: Claude Code says it's done. Check the diff, not the paragraph.


Originally published at singhlabs.dev.

Top comments (0)