COSMIC bans AI-generated pull requests: write your own AI code policy
System76's COSMIC desktop now rejects AI-generated pull requests. Here is what the policy says and why your team needs an AI code policy too.
An open-source project just told AI coding agents to stay out. System76's COSMIC desktop now rejects AI-generated pull requests. Every contributor must confirm that their PR has no LLM-generated content: not the code, not the comments, not the description. For a small business, the lesson is not "ban AI." It is "write the rule down before the review queue writes it for you."
What actually happened
The policy lives in the COSMIC pull request template. The first checkbox says the contributor has not included any LLM-generated content in the PR, "including code, comments, and descriptions." The other boxes ask contributors to confirm that they understand the change, can answer review feedback, have tested it, and accept the Developer Certificate of Origin.
Linuxiac reported the change on October 2. Per that report, System76 gave review burden as the reason: many AI-assisted PRs came from inexperienced contributors and were rarely merged. PRs without the confirmation can be closed without a merge. The rule has a carve-out for cosmic-flatpak, where upstream projects own the manifests.
Why it matters for your business
The real problem COSMIC names is not AI. It is a pull request the author cannot explain. An agent can open ten PRs an hour. A reviewer still reads them one at a time. When generation is free and review is not, the reviewer becomes the bottleneck, and quality falls behind.
You probably do not want a total ban. We use coding agents every day. But you need a written policy, and COSMIC's checklist is a good place to start:
The author owns the change. Whoever opens the PR must be able to explain every line, AI-written or not.
Disclose agent use. Add a checkbox to your PR template. It costs nothing and tells the reviewer where to look harder.
Tests are not optional. Agent-written code with no test is a guess.
Check your dependencies. If you ship open-source code, read the contribution rules of the projects you depend on before your agent opens PRs against them.
Key takeaways
- COSMIC's PR template now requires contributors to confirm no LLM-generated code, comments or descriptions
- Per Linuxiac, the reason is review burden from low-quality AI-assisted PRs
- PRs without the confirmation can be closed without a merge
- The bottleneck in AI-assisted development is review, not generation
- Write an AI code policy: author owns the change, disclose agent use, require tests
Coding agents writing more than your team can review? We set up PR templates, CI checks and agent guardrails so AI-assisted code ships at the speed you can actually review. See what we build, or tell us about your workflow.
Sources: COSMIC pull request template (GitHub), Linuxiac.
- #ai-generated-code
- #open-source
- #code-review
- #ai-code-policy
- #system76
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
TA419 faked an Anthropic exec to phish: MFA codes didn't help
Proofpoint says China-aligned TA419 impersonated an Anthropic employee and used browser-in-browser phishing to steal MFA codes and sessions. Move to passkeys.
Read itMicrosoft settles Cerence TTS suit: track your license end dates
Microsoft and Nuance agreed to settle Cerence's text-to-speech copyright suit over use after a license expired. Track the end date on every license you ship.
Read it