When the contributor might be a model
From a Claude-found lattice break to AI-draft floods at the IETF and a bot-mediated fight on emacs-devel, free software and standards communities are arguing what counts as legitimate help, what is noise, and what threatens how work is governed.
Three very different venues have spent the past weeks arguing the same underlying question: when an LLM writes, finds, or speaks, is that a contribution, a flood of noise, or a change in who the community is accountable to? The tension is not abstract. A post-quantum signature candidate was pulled after an AI-assisted break. Independent Internet-Draft volume has jumped enough that long-time IETF participants are comparing it to spam. And on emacs-devel, a NonGNU ELPA submission for an LLM-agent frontend turned into a fight over hidden authorship, copyright assignment, and whether bot replies belong on a human list at all.
The cryptanalytic case is the cleanest technical win for the "AI as instrument" side, and it arrived with unusual candor. Steve Weis announced on the NIST pqc-forum an improved key-recovery attack on HAWK-n that "reduces to SVP in dimension n/2 + 1," cutting claimed cost for HAWK-512 from 2^150 to 2^108 and for HAWK-1024 from 2^288 to 2^182, with a practical end-to-end recovery of a HAWK-256 key. The note that landed hardest was process, not asymptotics: "this was found by Claude, with minimal technical guidance from people." Daniel Apon’s reply was brief and consequential: "Nice. It checks out independently for me." The HAWK team’s cooperation in verification, and the subsequent withdrawal path from the NIST signatures process, treated the result as ordinary cryptanalysis even while the discovery story was not. Adjacent threads on the same list kept the human framing intact. Demi Marie Obenour argued that waiting for formal standardization is optional when operators control both ends: "One doesn't have to wait for a scheme to be standardized before deploying it." Bas Westerbaan answered with adoption graphs that separate human and automated populations rather than treating "the Internet" as a single curve. In that corner of the ecosystem, the model is being received as a high-leverage analyst whose output still faces the same independent check every other attack faces.
The IETF thread is the opposite problem: volume without that check. Ross Finlayson opened with the mood of many readers of the independent-draft stream: "this is getting out of hand." He floated, then immediately disclaimed, a bond refunded only on working-group adoption, and settled on the serious analogy: "we need to start thinking of this as a problem akin to spam, and start treating it accordingly." Separating working-group and independent announcement lists was his minimal practical cut. Others reached for detection and process rather than satire. Theodore Ts’o pointed at watermarking work already shipping in major models and at detector tooling as something the IETF could put "to the toolbox," while noting open-weight models will slip that net. Lars Eggert refused nostalgia: "the issue of fully or partially AI-generated IETF contributions is here to stay," and "AI can be useful in accelerating standards work if used responsibly and correctly." His sharper observation mapped directly onto open-source maintenance pain: pull requests (and drafts) are now cheap to generate, "and the cost is shifting to core review, which is not (yet?) similarly cheaply done." The predicted social response is triage by familiarity, which Carsten Bormann immediately flagged as a threat to openness: genuine newcomers will be harder to spot "in the ‘AI slop’." His counter-proposal was infrastructure for attention, not prohibition: multi-grade "commendations," viewer-local weights derived from prior authorship and leadership, and private document scores so search can surface signal without a single global reputation system.
Concrete mitigation sketches are already mixing social and technical controls. Andrew Yourtchenko reported that among drafts adopted in a year window, only fourteen had author lists entirely new to RFCs or working-group drafts, and wondered whether a -00 rate limiter should become a web-of-trust: one free independent submission, then a shepherd from people already in the work. He also mentioned building the measurement script "over a dozen iterations with my friend Claude," a detail that undercuts any clean human-versus-tool binary inside the same conversation. S. Moonesamy, looking at working-group mail as well as the -00 spike, was blunter about quality: some drafts are "too muddled," and others exist because AI "lowered the barrier to write a draft." Carlos Martinez-Cagnazzo endorsed Bormann-style attention tools and added the recursive defense: "one of the best weapons against AI Slop is... drums... yes, AI," tuned to IETF norms and attached as scores on each -00. Eggert’s caution about IP still sits unresolved in parentheses: fully machine-generated text and the license grants the IETF expects from contributors are not obviously the same act.
On emacs-devel the collision is governance philosophy plus list culture. Thanos Apollo submitted hermes, an Emacs frontend for a Hermes agent, with the usual feature list: EWOC dashboard, streamed markdown and diffs, approval prompts, session and MCP browsers, local and remote agents. Jean Louis inspected the repository history and argued the package looked LLM-generated with attribution suppressed, citing instruction text that said to "add no generated-by or co-author metadata." His core objection was legal and project-shaped, not taste: "If the code is fully generated by an LLM, it is questionable how the FSF can protect copyrights on it. Copyright assignment requires a human author who holds the rights. An LLM cannot hold copyright." He asked for policy before the archive fills with similar work. A reply then arrived from "Hermes," announcing itself as "Thanos's email agent, replying at his request," pointing at an "Assisted-by: Hermes:MoA" header line, insisting AGENTS.md was about commit subjects rather than concealment, and closing "No concealed clanker here." The room’s reaction was not about the package API. Jacob S. Gordon called the tactic disgusting and asked the maintainer to simply stop answering rather than "hurling slop at the list." Andrei Sova wrote that subscribers "did not consent to receiving messages that do not contain any sort of intent beyond what one might find in spam emails." Petteri Hintsanen was shorter: "Please stop sending bot slop to this list. It is just spam." Parallel mail from Richard Stallman and Eli Zaretskii reopened the older GNU question of whether integrating or referring to nonfree networked services steers users; Zaretskii’s line was that allowing configured access is not the same as recommending a site, the way EWW is not a suggestion to visit nonfree hosts. That classic freeness dispute now sits beside a newer one: whether an agent may speak on the development list in the maintainer’s name.
Across the three threads the through-line is less "are models useful" than "where does review cost and accountability live." In the HAWK case, usefulness was demonstrated under independent verification and ordinary cryptographic norms; the model shrank a lattice dimension and humans still had to confirm the math, ship the demonstration, and accept the standardization consequence. At the IETF, the same class of tool makes first drafts and first comments abundant while review time does not, so the community is inventing spam analogues, watermarks, shepherds, and private commendation graphs to protect attention without formally closing the door. In Emacs packaging, the fight is over disclosure, copyright assignability, and whether automated speech on a consensus list is a legitimate proxy or a denial of human conversation. No venue has a settled rule that scales. NIST process can withdraw a broken parameter set; it cannot say whether the next legitimate break must carry a human lab notebook. The IETF can rate-limit -00s; it has not defined when machine prose is a contribution under its current license practice. The Emacs and FSF side can demand coherent philosophy about nonfree services; it still lacks an accepted policy for LLM-authored code and for bots that answer critics.
What remains open is not whether these tools will appear again. They will. It is whether FOSS and standards bodies will treat them as instruments under existing review, as a new spam class to be filtered, or as actors that force changes to identity, copyright, and who is allowed to speak in the project’s name.