COSMIC Desktop Bans AI-Generated Code Outright: Maintainer Overload or an Open Source Identity Crisis?

System76's COSMIC desktop project now requires contributors to certify in their pull requests that no LLM-generated content is included, citing maintainer

In October 2026, System76's COSMIC desktop project updated its contribution rules, adding a mandatory declaration checklist to its pull request template that requires all contributors to attest that they have not included any LLM-generated content in the PR, including code, comments, and the PR description itself. The ban covers nearly the entire codebase, with only cosmic-flatpak exempt because its upstream project manages its own checklist.

COSMIC is the next-generation desktop environment behind the Pop!_OS operating system, built from scratch in Rust by System76, and is currently in an intensive development phase. The project's contributor agreement requires checking off each of the following items: no content was generated using an LLM; the submitted changes are fully understood and the contributor can respond to code review comments; the commit message accurately describes the changes; the changes have been tested; and all terms of the Developer Certificate of Origin have been read and complied with.

Maintainer Overload: The Immediate Trigger Behind the Ban

In explaining the decision, System76 chief engineer Jeremy Soller pointed directly to a real predicament: the spread of LLM tools has brought in a flood of contributors who had never previously taken part in the project, but the content they submit is "unplanned and rarely accepted." The problem is not how poor the quality of these submissions is, but that every PR, regardless of quality, requires maintainers to spend time reviewing, testing, and replying — and when submission volume rises sharply while the acceptance rate stays low, the marginal burden on maintainers climbs steeply.

This predicament is not unique to COSMIC. Linux kernel maintainers have likewise reported being flooded by AI-assisted submissions, and Ubuntu has accelerated its update cadence to work through a backlog of incoming issue reports. The difference is that Linux and Ubuntu chose "conditional acceptance" — AI-generated content is allowed through review as long as quality standards are met — while COSMIC chose to block the entrance outright.

COSMIC's ban is not aimed at AI tools themselves but at "generative" uses. Non-generative scenarios such as using AI to help find defects or understand code are not prohibited. This distinction shows that what System76 is trying to block is the specific behavior of "having AI write code that is then submitted," rather than rejecting AI tools wholesale.

The Deeper Legal Risk: Can the DCO Cover AI-Generated Code?

Maintainer burden is the surface reason, but whenever the open source community discusses this issue it cannot avoid a more fundamental legal question: can the Developer Certificate of Origin legitimately apply to AI-generated code?

The DCO requires contributors to sign and certify that they have the right to submit the code under the project's license and that the code's provenance is clear. The problem is that mainstream large language models are trained on vast amounts of open source code, including code bound by restrictive licenses such as the GPL. When a developer has AI generate a piece of code and submits it, they cannot actually trace where that code came from, and therefore cannot honestly make the ownership declaration that signing the DCO requires.

Red Hat noted in an analysis that the DCO has historically not required every line of code to be the contributor's own creative expression, but a number of legal observers argue that for AI output whose provenance cannot be traced at all, signing the DCO poses an integrity risk. The NetBSD project went further and banned AI-generated submissions before COSMIC did, on "copyright contamination" grounds — its maintainers argue that the opaque licensing status of training data makes AI output legally "unknown-provenance" content.

A Route Split in the Open Source Ecosystem

COSMIC's choice makes the divisions within the open source community clearer. Based on existing reports, the Linux ecosystem has already formed two distinct camps on AI policy.

On one side is a group of projects with explicit bans: aerynOS explicitly prohibits "content generated by probabilistic tools such as ChatGPT, Claude, and Copilot"; Chimera Linux stipulates that "contributors found using LLMs will be permanently banned from participating in the project"; Elementary OS does not allow "contributions generated by LLMs and chatbots"; Gentoo bans "any content assisted by natural language processing AI tools"; Nura prohibits "contributions created in part or in whole by generative AI"; and secureblue states that "any form of AI-generated code or content is prohibited."

On the other side is the pragmatic route represented by the Linux kernel. In 2026 the Linux kernel established a formal policy on AI-assisted code, whose core mechanism is a new "Assisted-by" tag — AI-assisted code cannot carry the legally binding "Signed-off-by" tag and must instead be labeled "Assisted-by," placing all responsibility squarely on the human developer who submits the code. The policy took shape after months of heated debate: Intel's Dave Hansen and Oracle's Lorenzo Stoakes clashed publicly, and Linus Torvalds finally ended the argument in his usual blunt style, calling a blanket ban on AI "meaningless posturing" and framing AI as "just another tool" — bad actors submitting junk code were never going to read the rules anyway, and the key is to hold human developers accountable for their own submissions.

The logic behind these two routes deserves closer scrutiny. The Linux kernel's approach redefines the issue as a question of accountability: whether AI is used does not matter; what matters is that a person is responsible for code quality. COSMIC's approach defines it as a question of operating cost: regardless of AI code quality, the screening cost itself is an unacceptable burden, so cutting off the source is more economical than reviewing. Both answers are internally coherent, but their preconditions differ — the Linux kernel has decades of accumulated high-bar review culture and a large corps of maintainers, while COSMIC is a relatively small project still in a rapid build-out phase.

What This Means for Different Stakeholders

For individual developers hoping to contribute to COSMIC, this rule means they must remain clearly aware of the provenance of all code before submitting. Developers accustomed to using AI to "get up to speed" quickly on open source projects will face a higher barrier to entry. This will filter out contributors with a shallow understanding of the project itself who rely mainly on AI-generated submissions — which is precisely the effect System76 is aiming for.

For enterprise users and organizational contributors, the situation is more complex. More and more companies have deeply integrated AI-assisted programming tools into their development workflows, and requiring employees to "switch them off manually" when contributing to a particular open source project involves a degree of ambiguity at the implementation level. There is currently no reliable technical means for contributors to prove that their code was entirely not AI-generated — the ban in essence relies on the community's good-faith self-discipline rather than technical enforcement.

For the overall competitive landscape of the open source ecosystem, this split means developers will face a new dimension when choosing which projects to take part in: what is this project's AI policy? Ban-leaning and open-leaning projects may gradually develop different styles of contributor communities, which in turn affects their respective development speed and code style.