OpenSSL Communities

Proposed AI policy

Jon EricsonJon Ericson Wed 13 May 2026 12:39AMPublicSeen by 114

There is now a proposed AI policy. For discussion of the details, please direct your comments to the PR itself. This discussion thread is a continuation of an earlier discussion. In a relatively short period of time we seem to have arrived a point where some allowance for AI seems necessary. Better to require people disclose the AI model(s) they have used and sign an updated CLA than pretend people aren't already contributing AI-assisted code.

Dmitry Belyavsky

Dmitry BelyavskyWed 13 May 2026 5:35AM

What I don't like in the idea is the resigning of the updated CLA. People are negative to the current CLA approach, and resigning will not make the situation any better

Tomas Mraz

Tomas MrazWed 13 May 2026 8:22AM

@Dmitry Belyavsky Only those that want to submit work generated by AI will need to sign CLA again. I do not think there is any way around that. Furthermore, we recently do not have any issues with signing CLAs. It was quite a while ago when we saw somebody not willing to sign a CLA. And, frankly, with AI we already have a lot of contributors, more than we can actually currently handle as for reviewing.

Peter Gutmann

Peter GutmannWed 13 May 2026 8:48AM

Could the existing CLA be taken to mean "does not include AI", so only contributors wanting to use AI would have to sign the updated CLA? That would restrict the disruption to only those affected by it.

Matt Caswell

Matt CaswellWed 13 May 2026 8:52AM

@Peter Gutmann that is exactly what the proposed policy says: "The old CLA remains valid for contributions that do not include non-trivial AI-generated content. If you are not using AI assistance, there is no need to re-sign."

Peter Gutmann

Peter GutmannWed 13 May 2026 10:41AM

@Matt Caswell Ah, reading comprehension fail, it's further down in the "The CLA Requirement" section.

Craig Lorentzen

Craig LorentzenWed 13 May 2026 1:56PM

I may have missed it, but Can someone share the updated CLA that we are referncing in the ai-policy? I still see only the 1.0 policy from https://openssl-library.org/policies/cla/

Matt Caswell

Matt CaswellWed 13 May 2026 2:01PM

@Craig Lorentzen It hasn't been issued/written yet. As noted in the PR "This presupposes the existence of some version of the CLA with an AI clause", i.e. we know we need one, but haven't issued it yet.

Richard Levitte (individual)

Richard Levitte (individual)Wed 20 May 2026 8:39AM

@matt s/It has/It hasn't/

Matt Caswell

Matt CaswellWed 20 May 2026 8:53AM

@Richard Levitte (individual) Fixed!

Josef Edwards

Josef EdwardsThu 14 May 2026 8:32AM

This is excellent! Thank you for sharing this email! All of my comments on the OpenSSL repo were not AI generated. The little bit of allowance I was asking for was just one iteration help with a new dot c file for the atomic operations. I will elaborate on the discussion PR further if @drqedwards is not blocked on there anymore

Load More