The AI Pascal’s Wager

30 points by cgrinds


emk

When you think about it, contributors who are completely turned away by the fact that they can’t use LLMs are probably contributors you don’t want in your project, even if you have a Debian-like “moderate use of AI” position.

If a project says, "No AI," then I absolutely respect that. Nothing which has been touched by AI in any way will be sent to that project. This is pretty clearly what a lot of people with that policy want. They ethically object to any use of LLMs. It's a matter of moral purity, not a practical question. I wouldn't offer them something that involved AI at any point any more than I would offer a vegan something that had touched butter.

Let me give you an example: I was working on a distributed word frequency estimator. Before I left for a meeting, I asked Claude to check the distributed counts and see if it could find anything interesting. Claude found some weirdness in the numbers, and—completely unasked—it started digging around in one of the open source libraries I was using. It found a nasty and very subtle bug in the open source library.

So now I have a problem: I know about a serious bug. But it was found entirely using AI. As lawyers like to say, it was "fruit of the poisoned tree." There is no way that I can retroactively remove AI from the process.

Now, that author had no policy against AI contributions. So I hand-wrote a nice bug report and offered to fix it. Fascinatingly, Claude made a subtle mistake in its proposed fix to the algorithm. But both I and the upstream author made exactly the same mistake Claude did the first times we tried to fix it. The only thing that actually fixed the bug was when I (or maybe Claude at my request?) wrote some proptests, which found a super tricky edge case. (I actually think the incomplete fix is present in some academic papers about the algorithm, IIRC. I'm still not even 100% sure that the final fix was correct, but it holds up under a quarter million randomly generated test cases checking various mathematical properties, which is a good start.)

So that's my dilemma: Sometimes a coding agent will find bugs in someone else's code. These may be subtle correctness bugs, or data corruption bugs, or serious security vulnerabilities. And if I discover one of these bugs, there's a decent chance AI will be involved in some way. This is because my first reflex when someone else's library does something weird is to ask the nearest coding agent to take a look. Life's too short to debug things like treesitter myself when an agent will almost always find the problem in 2-5 minutes. I may have to fix the problem myself, and of course I'll write my own commit messages and PRs.

But if you have a strict zero AI policy, then I'm going to assume that you're doing it on moral grounds. Which puts me in the awkward position of knowing that your code is computing incorrect answers, or corrupting user data, or leaving your users vulnerable to attack. And then I have to guess whether you want to know about a bug discovered using AI. If you have a strict no-AI policy, I'm not going to hide the AI use.

In practice, if it's a security bug, I'll probably verify the bug carefully by hand and disclose it to you via a private channel, if I can find one. For other bugs, I may switch to another library, or just quietly fork yours. Which feels antisocial. But given how many "no AI" policies feel like ritual purity laws (nothing wrong with ritual purity laws!), I don't want to inflict AI-discovered bugs on people who are strongly anti-AI.

On my personal projects, I actually have a mix of AI policies. I will normally close slop feature PRs without reading. Slop bug-fix PRs, well, I'll either read them myself, or if the PR is too annoying, and confused, I'll ask my own agent whether the "bug" is real. A few of my projects are "learning" projects, and these will forbid all AI-written code, because the point is learning. Or sometimes my policy is "trusted maintainers can use AI if they want, but we'll reject slop feature PRs from other people."