If you have been following our newsletter, you might be aware that we recently added an AI Usage Policy to our project. This follows a lot of other projects doing likewise and took several months of discussion by the Zeek Leadership team and the development team.

In this post I want to take a bit of a step back and talk about why we need an AI usage policy.

Before we start – let me preface this article with the fact that we recognize that AIs/LLMs are incredibly powerful tools that are transforming how software is written and how security issues are discovered. They also change how people learn things, solve problems, and interact with communities. For our users, AI assistants also transform how the data that Zeek outputs is used. The Zeek development team uses AI tools to help with discovering bugs and with developing features – and holds itself to the same policy.

However, while AI tools are powerful, they can quickly expose human constraints, especially in open-source projects. AI tooling can make it easy to generate a significant amount of code or other submissions – which can easily overwhelm maintainers.

One of the reasons that we decided to publish this policy is to set boundaries and expectations around the use of AI. Each pull request, each discussion, each Slack message for our project is reviewed by one (or often several) of our team members. We are happy to help with problems, to get submissions into the correct shape or to discuss use-cases.

However, AI changes the game and makes it easy to use tools in an inconsiderate way. For example, by submitting a fully automatically generated pull request without reviewing the code, or by letting AI tools try to write a Zeek script that doesn’t work – and pasting it as a question to our Slack without trying to understand what it does.

When this happens, the entire burden of reviewing work, understanding/solving a problem is shifted to the maintainers of Zeek. This is obviously not viable, and also not fair to the maintainers.

For these reasons, we require disclosure of AI tooling, and to what extent it was used. The human using an AI has to have reviewed and understood contributions before they are submitted to us and must be able to explain them.

We are grateful for our community, and for any contributions to the Zeek project. By implementing this policy, we want to make sure that the project stays as approachable as it currently is in the future.

If you have any comments or concerns about this policy – please let us know either on Slack, or by emailing us at lt@zeek.org.

 

Author

Discover more from Zeek

Subscribe now to keep reading and get access to the full archive.

Continue reading