root: add AI_POLICY.md (#23481)

Co-authored-by: Dominic Roy <dominic@goauthentik.io>
Co-authored-by: Fletcher Heisler <fheisler@users.noreply.github.com>
Signed-off-by: Marc 'risson' Schmitt <marc.schmitt@risson.space>
Signed-off-by: Fletcher Heisler <fheisler@users.noreply.github.com>
This commit is contained in:
Marc 'risson' Schmitt
2026-08-03 21:48:58 +02:00
committed by GitHub
parent ea2a25785c
commit 7c2c7f91e7
2 changed files with 22 additions and 0 deletions

21
AI_POLICY.md Normal file
View File

@@ -0,0 +1,21 @@
# AI-Assisted Contributions Policy
authentik welcomes community contributions, including AI-assisted contributions, as long as contributors understand, review, and take responsibility for what they submit.
- **All AI usage in any form must be disclosed.** State what tool(s) you relied on and the extent that the work was AI-assisted.
- **The human-in-the-loop must fully understand all code.** If you cannot explain what your changes do, why they are correct, and how they affect the relevant parts of authentik without AI assistance, do not submit them.
- **Issues and discussions can use AI assistance but must have a human-in-the-loop.** This means that any content generated with AI must have been reviewed _and edited_ by a human before submission. AI is often overly verbose, with noise that distracts from the main point. Contributors are expected to verify claims, include relevant context, and remove generic or speculative content.
- **No AI-generated media is allowed (art, images, videos, audio, etc.).** Text and code are the only acceptable AI-generated content.
- If a code contribution or discussion appears to be entirely AI-driven and lacking human judgement, the maintainers will close the issue/PR/discussion. Common examples include unexplained large diffs, invented API endpoints, irrelevant changes, generic issue reports, repeated AI-generated replies, or contributors being unable to answer review questions.
These rules apply to all external contributions to authentik. Our [maintainers](https://github.com/orgs/goauthentik/people) use AI tools at the internal team's discretion; we are already constantly discussing our work with each other and checking in as humans.
## There are Humans Here
authentik is maintained by people with limited time and attention.
Every discussion, issue, and pull request is read and reviewed by humans (and sometimes machines, too). It is a boundary point at which people interact with each other and the work done. It is disrespectful and unscalable to approach this boundary with low-effort, unqualified work, since it puts the burden of validation on the maintainer.
**Our reason for the strict AI policy is not due to an anti-AI stance**, but instead due to the number of highly unqualified AI-driven contributions. A small minority misusing these tools creates an unscalable problem for maintainers.
In a perfect world, AI would produce high-quality, accurate work every time. But today, that reality depends on careful consideration and usage by the human driver of the AI. Since AI is instead best as _producing code quickly_, we have to have strict rules in place to protect the project and maintainers' limited time.

View File

@@ -179,6 +179,7 @@ uisp
unenrollment
unhashed
unmigrate
unscalable
unskippable
unsynchronized
uperm