To Ban or Not to Ban? How Open Source Projects Govern GenAI Contributions
Generative AI now writes code, opens issues, files pull requests, reviews changes, and even reports vulnerabilities in open source projects. But cheaper generation does not mean cheaper review. Under the growing maintenance burden, projects have started writing GenAI-specific rules — in CONTRIBUTING files, security policies, PR templates, and AGENTS.md — ranging from mandatory disclosure all the way to total bans.
To understand what is actually emerging, we read the AI rules of 67 of the most visible open source projects, along with the incidents and debates behind them. The picture goes far beyond ban-or-not. Maintainers’ worries cluster around seven pressure points in the contribution workflow, from unreviewable PRs to fabricated security reports. Projects respond with three distinct mindsets — keep it out, let it in with conditions, or judge the contribution rather than the tool — put into practice through twelve concrete strategies: disclosure checkboxes, evidence requirements, PR limits, agent-facing instruction files, and more. Each choice carries real trade-offs, and copying the strictest policy you can find is usually a mistake.
Whether you are a maintainer, PMC member, community builder, or OSPO practitioner, you will leave with a clear map of what other communities are doing, the trade-offs behind each option, and a practical starting point for the conversation in your own project. And before we close — one more thing: a first look at what actually happens when coding agents meet the rules you write.
Speakers:

Wenhao Yang: Peking University, PhD Candidate
Wenhao Yang is a Ph.D. Candidate at the School of Computer Science, Peking University, and a member of Professor Minghui Zhou’s Open Source Software Data Analytics Lab. His research focuses on open source software communities, software governance, and the impact of generative AI on collaborative development. He studies how open source projects adapt their contribution processes, policies, and review practices in response to emerging AI-assisted workflows.

Runzhi He: PhD Candidate, School of Computer Science, Peking University
Runzhi He is currently a Ph.D. candidate at the School of Computer Science, Peking University, and a member of Professor Minghui Zhou’s Open Source Software Data Analytics Lab. He received his B.S. degree from the School of Electronics Engineering and Computer Science (EECS), Peking University. His research mainly focuses on AI4SE and software supply chains. He can be contacted at rzhe@pku.edu.cn.