Oracle, the law firm with a tech business attached, probably wants to retain the option to sue other people for AI-washing their proprietary code, and that doesn't work if they're also publicly accepting AI contributions to their code with no apparent concern for the provenance of it. The tech business would probably tell them this isn't going to be a needle they are going to be able to successfully thread, but the law firm is in the driver's seat.
"Do not fall into the trap of anthropomorphizing Larry Ellison. You need to think of Larry Ellison the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn - you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower hates me' - lawnmower doesn't give a * about you, the lawnmower can't hate you. Don't anthropomorphize the lawnmower. Don't fall into that trap about Oracle." --Bryan Cantrill
What about a guy with a lawnmower intentionally chopping off your foot? And what about a CEO making decisions on behalf of the corporate entity called Oracle?
It doesn't matter if the lawnmower is chopping off feat intentionally or not. If it's presenting a public hazard, it should be stopped. Even though the ocean couldn't care less it doesn't prevent us from building breakwalls. And Larry Ellison isn't unstoppable as the ocean.
Rather than harmless, what the lawnmower analogy achieves is to make him seem blameless. "How can you assign blame to a thing that's just doing what it's built to do without any intent?" It's important to push back against that. Intent isn't a necessary condition for something to be dangerous. A rabid dog will be put down regardless of blame.
Never thought to hear someone here mention Maximum Overdrive. Indeed a hilarious movie and the only movie for which AC/DC ever recorded an (instrumental) soundtrack.
The flaw in the analogy is that oracle is made of people. It's not a lawnmower, it's a group of people with human motivations and human thoughts. It's true they don't HATE people, but it's also true they absolutely have no conscience in negotiations and have zero concern about relationships.
Maybe so, but perhaps the most successful part of the AI marketing pitch has been exploiting management's hatred of labor (and vice versa).
A significant motivator for a lot of the nonsensical AI layoffs and initiatives over the last three years has been that it's a great opportunity for management to get ill on their slaves.
Tech labor got a little too big for their britches during the hiring spree of 2021, and AI was a great opportunity to take them down a peg, even if it offered little in the way of ROI.
He's talking about the owner of Oracle, not the people who work there. It doesn't matter how many smart and talented real humans work at Oracle, the guy running it acts like a fleshy paperclip optimizer.
How many bureaucracies in history have behaved in deeply misanthropic ways, especially when led by misanthropic leaders?
Don't underestimate the power of the desire to keep one's job to cause a large organization to behave towards its own self-perpetuation despite the moral lines that must be crossed by individuals to do so.
> How many bureaucracies in history have behaved in deeply misanthropic ways, especially when led by misanthropic leaders?
Lots!
> Don't underestimate the power of the desire to keep one's job to cause a large organization to behave towards its own self-perpetuation despite the moral lines that must be crossed by individuals to do so.
That’s an interesting story to bring up in this context, because I have always wondered how a fundamentally customer-hostile business like Oracle could be so successful. It really puts the lie to libertarian cliches about the invisible hand of capitalism that ends up being philanthropic in spite of itself.
The lawnmower exists, you might disagree, but it’s not your lawnmower, you can’t uncreate it. But you can and should take care never to put your hand near it.
It’s been established that LLM-generated code is not copyrighted so I can fully understand the company living from copyrighted data to not accept LLM-generated contributions.
> It’s been established that LLM-generated code is not copyrighted
If that's a reference to Thaler v. Perlmutter, the only thing that's been established is that an LLM can't be considered an author under the Copyright Act, only a human being can. It says nothing about the consequences of a human claiming authorship of LLM-generated code, which would be relevant here.
My understanding (belief) is that it's going to depend on how much human involvement is there.
If you write a prompt and one-shot a problem and share the source code, that source code is probably not covered by copyright.
If you substantially edit or modify the generated code you would own the copyright.
It's like with a camera. If I set a camera and carefully aim it and somehow trigger the shutter then make adjustments in Photoshop, I own the copyright on that image.
If I stick a Flock camera on a pole somewhere and post the live output, there's been no meaningful human creative involvement in producing those images and so nobody can claim copyright on them.
I think if I as a human use an llm to do something technical that would qualify copyright, it should still qualify for copyright. How do you decide how much human is copyrightable. If I use a package that writes code or use a library for some piece of it, I could still copyright.
I don't like this idea that llm code can't be owned by a human, copyrighted. It's just code.
I think your last example with flock camera is relevant here - I can take a picture of a public football as a reporter or something (or a fan I guess) and I can copyright and sell that picture. Newspapers do it every day.
So if I stand on a street corner and take a pic, it's copyrightable. If I take a pic using a flock camera it should also be copyrightable, just like if my nest camera at home takes a pic of something, I can use that.
I guess you are saying "someone else owns the flock camera" so you don't get to own pictures. What if I buy the flock-like camera and put it up, I should own that.
No, that’s not what they are saying. They’re saying that the code generated by a human with help from an LLM may potentially be. This is what I hope we are going to arrive at, eventually.
For those wondering what the difference is: consider what happens when an LLM regurgitates its training data. It's copyrighted... but not by the person who generated it.
This is a false narrative based on a (IMO often intentional) misunderstanding. It has by no means been established by any court that LLM-generated code is not copyrightable.
Thaler v. Perlmutter stands for a much narrower proposition and at any rate is not binding nationally, SCOTUS having denied certiorari.
This is not necessarily true. While no court has explicitly come out and said that copyright does not apply to AI-generated works of authorship, the US copyright office has[0]:
> Based on an analysis of copyright law and policy, informed by the many thoughtful comments in response to our NOI, the Office makes the following conclusions and recommendations:
> • Questions of copyrightability and AI can be resolved pursuant to existing law, without the need for legislative change.
> • The use of AI tools to assist rather than stand in for human creativity does not affect the availability of copyright protection for the output.
> • Copyright protects the original expression in a work created by a human author, even if the work also includes AI-generated material.
> • Copyright does not extend to purely AI-generated material, or material where there is insufficient human control over the expressive elements.
> • Whether human contributions to AI-generated outputs are sufficient to constitute authorship must be analyzed on a case-by-case basis.
> • Based on the functioning of current generally available technology, prompts do not alone provide sufficient control.
> • Human authors are entitled to copyright in their works of authorship that are perceptible in AI-generated outputs, as well as the creative selection, coordination, or arrangement of material in the outputs, or creative modifications of the outputs.
> • The case has not been made for additional copyright or sui generis protection for AI-generated content.
> The Office will continue to monitor technological and legal developments to determine whether any of these conclusions should be revisited. It will also provide ongoing assistance to the public, including through additional registration guidance and an update to the Compendium of U.S. Copyright Office Practices.
Congress or the courts could, of course, override the stance of the copyright office, but I think it would be highly unusual for them to do so (particularly for something like this). It would however be a lot better if congress just stepped in and said no outright, but until then this will have to do.
Sure, but I would be incredibly shocked if the courts overturned these conclusions. These kinds of determinations are within the remit of the USCO, so a court does not need to come out and say it if the USCO has already done so. Obviously, as I said it would be better if congress weighed in and solved this problem, given that the USCO is free to publish a new NOI to change it's practices/policies, but we all know that congress is too gridlocked atm for that to happen
> Whether human contributions to AI-generated outputs are sufficient to constitute authorship must be analyzed on a case-by-case basis
It says a plain prompt is not enough but that is not the reality of real software development. People aren't one-shotting complex business apps. The vast majority of software development will trivially pass that bar and end up in the "requires case by case analysis".
You are a false narrative. I’m just repeating what I read. The thing is, it’s murky waters. Someone’s going to challenge it but do you want to be the guy who takes it on a chin?
The sibling comment lays this out and my original comment above is based on exactly the same link.
Also it's a different story intranationally for those of us who live in countries with much more restrictive/no fair use. Are you geolocking your software to the USA?
I highly doubt that that's the last word on that matter, but even if: Even before LLMs you could combine individual non-copyrighted components into something copyrighted.
Legal departments are ironically very much like LLMs.
They are trained on a narrow set of data and don't really understand the real world.
If you let them run wild with no supervision they'll turn your company into slop.
Someone needs to be there to reign them in, asking the all-important questions like "is suing all of our customers and making them angry REALLY the best option?" (to which they will reply, "You're right to push back on this").
This is typically the role of the CEO, however, as we know, most CEOs of large successful companies are too busy to actually do that. They're mostly training Brazilian Jiu Jitsu, shitposting on their own social media platform, trying to manipulate international politics, or helping run their family nonprofit.
This is why I believe that legal departments need to be demoted. The legal department should not report to the CEO, they should report to a new role that is above both PR and legal. And that person's job should be to force legal and public relations (which we know are natural enemies) to work together. Every press release goes through legal now, and it's only logical that ever legal action should go through public relations review as well.
The fact that public relations at most large companies has atrophied from disuse in our public-equity-owned unicorporate cooperation-over-competition chaebol/zaibatsu/conglomerate world is a problem for another day.
I guess that depends on whether you think the motivations matter. When it comes to a policy on a hot-button issue that seems like it could easily be enforced selectively, I don't think it's a stretch to be concerned about whether the one who crafts and enforces the policy for a project that's supposed to be open having a track record of being the cause of the issues supposedly that make the policy "sensible".
Some important context - it appears it applies to submissions from the community but possibly not to core developers:
> Contributions in the OpenJDK Community must not include content generated, in part or in full, by large language models
So this likely falls more into the category of the inability of the core maintainers to manage the voluminous submissions coming from community than some broad ban of use in AI to develop it at all.
I kind of get their overall point, even if it is ironic that Oracle is all in on AI. They don’t want a ton of contributions to review that weren’t made with care, adding burden to, as they put it: “already limited time of human reviewers”.
Especially for a project that runs to many major businesses, this could pose a massive risk.
I understand the intent of it. It's really annoying/rude when someone gives you a pile of AI generated crap and says "here, you figure it out." Anyone can type these prompts now, the hard part is figuring out if the output makes sense.
Seems like a better way to do this than ban all AI generated code, but it's probably a matter where they're far more concerned about their own inconvenience than someone else's.
Ghostty has what I’d consider to be a reasonable policy. You submit what you want to change and how, explain it in your own words. A trusted member can vouch for you. You can then make a PR, but you need to explain the solution and how it works in your own words.
I’m sure someone could still just prompt their way through but it’s a decent soft gate IMO.
Really, I think the long term solution is people's attitudes need to catch up with the technology.
Humans still need to review code for taste, making sure AI is writing sensible, well organized output. That's a core "AI skill" for now, at least until it gets better...
If ai rapidly gets better, then instead of submitting prs you can ask your agent to fork and improve the project and bypass the policy that way. if it goes slower they have time to reconsider policies in the future. if it doesn't improve then we can probably find out some middle ground approach like the ghostty one
in any of those cases there's no reason to get swamped by cheap PRs for now
> the hard part is figuring out if the output makes sense.
I think for Java specifically, it's also very much: which prompts make sense to write. Java has had a storied history of features that made future development hard. That's resulted in a culture where they like to think quite deeply about how to add a feature BEFORE they sanction any sort of programming.
We'll just get used to it and the problems won't seem so bad, even if they are. To bring it all back, it's just like using oracle software in your enterprise, after a while you forget how awful it is to work with them.
java never had that phase. If anything it had a full binary class (not even source, e.g. long and int are not compatible on binary level) compatibility. Generally you can take an application from '98 and run it nowadays.
It's only recent changes (jigsaw in java9 mostly) that were made them to drop some of that part.
yeah, oracle is literally betting the future of the company on OpenAI owning the majority of the AI market, so it's pretty strange to see such a ban. Their debt is already pretty much junk (and I'm not exaggerating, it is rated BBB- by s&p)
Not sure where u get your information. Oracle Java is OpenJDK with a support license from Oracle. It is widely used in enterprises, and it is updated regularly.
>The second biggest use is Apache Spark/Kafka, but with LLMs now, you can pretty much re implement all of that functionality in pure C.
Spark is written in Scala, precisely because distributed systems are best modelled as a set of pure functions with minimal references to state. This is also why part of the reason why it's ascending successor, Polars Cloud, is written in a functional language, Rust, rather than C.
Android development is also increasingly being monopolized by Kotlin, not Java.
I didn't know openjdk was developed by Oracle. I always thought it was a community implementation of java as opposed to Oracle's proprietary implementation.
It is a community implementation although the vast majority of contributions come from Oracle staff. RedHat, in particular, has made numerous contributions.
It was Sun's project before Oracle bought Sun. Sun worked a lot with Netscape back in the day to make Open Source Software happen at all. From 1998-2004ish, Netscape and Sun were the open source projects and the strongest proponents of the licensing and development models. Oracle absorbed all that good will with the purchase.
So contributions to OpenJDK have to be hand-written, while internally, Oracle uses AI generated code... I guess the logic is that employees who use AI generated code (theoretically) review their code better? The whole thing still seems a little strange.
No, their internal PRs have the same problem, but they are pushing an AI narrative from the c-suite and can hide the reality of their private code bases.
The "limited ROI on AI investment" articles will continue to percolate slowly into the brains of the LinkedIn hive-mind until we hit a tipping point, and then we'll finally shut up about how a handy dev tool with some decent use-cases is the dawning of the singularity that will replace all white collar labor and get back to actually building business value.
Let me guess: AGI is 2-6 weeks away, software development is solved, and anyone who disagrees with your enlightened perspective is a backwards-looking luddite.
No. I’m asking in good faith. I was skeptical in 2023, but took the approach of using it at least once a week, with all latest models to see the evolution. It’s obvious that the industry is moving that way, and at this point it would be a career-suicide for seniors+ to not be able to drive AI to achieve their objectives .
I’m not saying it’s good for everything, but we’ve gone very far in terms of capabilities in the last 3 years. Thinking otherwise will make me question others’ experience on how much they’ve used it so far.
your argument is basically: the industry is moving to it so we should get on board or be left behind
it would be more convincing if you had concrete examples of technical merit and quality/speed improvements that worked for you or your team that justify going all-in
I manage several teams of developers who use them every day professionally and use them for personal projects privately. Just last week, at the prompting of said devs, we had a working agreement conversation about curtailing the use of AI in our codebases because of rapid erosion of our teams' ability to operate, update and maintain codebases that had started to spill over with slop.
We have had multiple incidents of credential leakage, integration tests wiping live databases, comically broken code that passed vibe-written tests, documentation and code comments that were hallucinated and/or fake, and most importantly developers saying "we no longer know how this code works but it's massively bloated and unreadable and we can't tell you with a straight face that we can maintain it or fix it if it breaks." We have seen a flood of vibe-PRs from engineering adjacent teams that suddenly think they can code shipping prototypes into production that do not workdo not scale and cannot be maintained. I am personally writing the tickets to decom one of those today. Which is great, I love telling business "the progress that was reported to you was a lie, this shit never worked, don't shoot the messenger but also don't let this happen again."
I embrace GenAI as a productivity tool for people who know what they are doing. It's a +10-15% velocity boost. That's great! That's a big deal, devs are expensive, and that might push some kinds of business model over the threshold into viability. That's great!
It is not, however, transforming the profession as I know it, it is rather making my job harder and less pleasant and it is making my leadership dumber by the second.
Absolutely no comment on vibe business decisions / vibe OKRs / slop reports or the host of other garbage that has started to creep into professional life. I have had to have some very uncomfortably direct conversations with peers in leadership about using complete bullshit to make decisions, and it is very, very frustrating. Do you know how hard it is to convince someone that metrics their bot hallucinated don't exist and would be meaningless if they did? You can't convince someone of something they are incentivized to not understand. It's been very eye-opening in terms of who I can trust to actually make sense when it matters. I'm grateful for the clarity.
Meanwhile we are rapidly losing brainshare from the top because our principal/staff engineers are pissed off and have the bankroll to just leave. We aren't hiring and training younger engineers to keep the talent pipeline moving. Which boy howdy is THAT going to cost us unbelievable sums of dollars to fix in the medium-term future.
I am in the uncomfortable role of trying to make the best of this but it would be a metric ton easier if the narrative from the c-suite aligned with reality in any meaningful way.
this matches my experience at $work with others as well...
when i brought this up with my manager they just said "you need to engineer a better harness" and "aren't you cultivating your agents.md file? thats probably your problem"
which is to say, apparently we're holding it wrong...
> most importantly developers saying "we no longer know how this code works but it's massively bloated and unreadable and we can't tell you with a straight face that we can maintain it or fix it if it breaks."
To anyone reading this: If you couldn't see this coming three years ago, you don't deserve your job.
> We have seen a flood of vibe-PRs from engineering adjacent teams that suddenly think they can code shipping prototypes into production that do not work do not scale and cannot be maintained.
What a nightmare. Never forget that AI is for idiots.
You can get your coworkers to stop sending you slop (I've done it already on my team) but it's probably much harder to stop an onslaught of open source contributors.
Nonsense, it's easy: you just need a social process like Linux has. Patches are ignored unless you've proven yourself to somebody. Start by participating in technical discussions on IRC or the smaller mailing lists; do that for a while before you submit patches. For smaller projects: "if I don't know you, I don't merge you".
Linux's LLM policy allows AI-generated code because the project was never vulnerable to this DoS attack in the first place. They kept the social defense they've had for decades.
The killzone here is Github culture, where people decided it was normal to accept code from anonymous randoms with anime avatars. They're doomed.
I don't know. I think it makes sense to have a policy like this.
I haven't written a line of code myself in 6 months, but the point is that _you shouldn't be able to tell_
What I tell people at work: Using AI is good. AI can help you do things that you otherwise wouldn't have. It shouldn't be a crutch for thinking.
In that sense, people shouldn't be able to tell that you're using AI unless the tell is that it's _higher quality_ than if you had implemented it by hand.
A good example here is a well-written document that has a _ton_ of deep research behind it. Or code that has extensive tests that would have taken too long to write by hand for the task at hand.
It's bad when it's just "do this thing and post a PR" but I write my code with AI, look at it as a reviewer, offer suggestions, put those into my steering if needed, and I refine it. The way I see it, I'm the first reviewer on everything now before passing it off to another human for review.
There have been points where having AI rewrite something was slower than me doing it, but I'm already in the harness. The cost of waiting is almost zero.
What stops me from contributing to the JVM using AI written code that I understand and spent time manicuring? Can a human really tell that it's AI written?
I believe thats the real reason, its not just Oracle, it would eventually be everyone in this kind of boat. No business would publicly use (or claim) AI to write code with recent verdict over the IP rights of AI generated code.
It would be interesting to see how this effects the copyleft Licences with contributors are using AI for the PRs
> AI to write code with recent verdict over the IP rights of AI generated code.
Which recent verdict?
> It would be interesting to see how this effects the copyleft Licences with contributors are using AI for the PRs
I know Linux and GCC have been diligent about tagging and tracking LLM based contributions. In the worst case they can chuck it all out and handwrite it back.
There is this old one around contents like images and all, the ripple affect is pretty much everywhere.
Its sort of coupled with the recent penalty of $1.5B on Anthropic. The catch 22 is that some portion of the LLM training data can be classified as IP theft. Even though Anthropic has been fined the data still exists and can be used by LLM to generate code for you. So if you are claiming something as an IP and it has stolen part in it then it leaves you in a hard place.
Language translations may save you in some cases, though the whole definition of cleanroom has been in debate recently too where people are trying to rewrite opensource/famous libraries in different language and claiming IP rights over them.
Anthropic will have judged the benefits of the settlement, not just the headline cost. It could have been a strategic move by Anthropic: we can't know without information we don't have. https://news.ycombinator.com/item?id=49014389 1.5B looks like ~2% of funding/income.
I understand the legal terminology is different, however at the same time I am not entirely sure if the optics change by calling it Settlement or Penalty. There is only one party paying money here and they are not getting any service after paying this money so its indeed a penalty for what they did before. Any article describing the details has both the key words, its a legal settlement where Anthropic is penalized.
Secondly the future is still not here yet, the people who came forward to sue are mostly in the category of book publishers/authors. The tech companies are are not actively searching for copyright thefts as of yet, however I am sure its just a matter of time when the big blobs of codes get rediscovered specially in case of any publicly visible code
The legal team in the Bartz v. Anthropic case was a coalition of three law firms, funded on a contingency fee basis, which ended up earning them $187 million (12.5%).
Other copyright lawsuits against other major companies are happening.
If a similar lawsuit costs OpenAI more than 1.5B then perhaps Anthropic is better off in their competitive race?
> the people who came forward to sue are mostly in the category of book publishers/authors
Irrelevant. The financially savvy parties are the lawfirm L.L.P.s trying to win money for themselves.
This constitutes an admission on the part of one of the largest AI investors that AI generated/"assisted" code is inadequate (in part) because it is produced in flagrant violation of license rights.
Using AI is vanity? I've never heard that before. Why is that?
Refusing to use AI honestly seems more like vanity to me. Like "no machine could ever do what I do".
That said I would not necessarily accuse people who don't want to use AI of vanity - there are good reasons not to want to use it - but if someone else did it I'd find it easier to understand.
It’ll be a licensing/copywrite concern. Large corporations using GenAI have guardrails and indemnity from their providers to protect them. Taking external contributions is more problematic, at the moment at least. So, in a standard lawyerly manner they shut it down until safe to do so.
It's hardly a surprise to see a behemoth like Oracle doing this.
Accepting LLM contributions can only be a liability, particularly for such a mature, stable project. Even if you see that liability as small or insignificant, it's non-zero. Given the project and the company, choosing zero additional liability seems like the obvious choice.
One also assumes the people maintaining OpenJDK have had their workload increase to an unmanageable level, like a lot of other free software projects and one thing I'm sure everyone can agree on is that Oracle certainly won't want to pay anyone more or hire more people to deal with that.
A lot of people (including the Register[0]) are pointing out that Oracle leadership are gung-ho about using LLMs for everything, and this seems to go against that.
It makes sense to question this from a journalistic angle -- the executives are obviously full of shit and people would do well to remember that the next time one of them opens their mouth. But pointing at the apparent contradiction -- different rules for internal projects vs. open ones -- doesn't seem particularly meaningful on its own:
I don't think the CEO/CTO raving about LLMs should be taken as firm statements about how they actually operate internally. I'm surprised that this does not seem to be the default case.
Among other things, Oracle stands to profit from greater adoption of LLM tools.
It would be unrealistic/unreasonable to expect their employees/contractors working on internal projects to be held to the same standard/guidelines/rules as developers contributing to a free software project.
This applies either way, whichever side (internal/open) has the worse deal.
I don't know what the rules are for their internal teams. As far as I know, I'm not alone in that.
Oracle also don't need to post anything publicly to change those rules.
> I feel like that was the epitome of AI assisted but quality code
I totally agree with you on this! The engineer is still actively engaging while getting the performance gains of not having to type out functions. The Engineer is still in charge vs agentic "engineering" a model + harness can spit out whatever and the engineer is left to review tons and tons of code
The Oracle antipathy is less about the policy itself and more about the apparent hypocrisy of hyping and funding these tools as "solving programming" and then forbidding their use on their own open source project.
How does all this AI generated code blocking gappen? Does a human decide that or an AI is tasked with sequencing that PR's DNA to ascertain its possible inhuman origins?
What if someone generates code with AI and then goes into the IDE and then bathes it, dresses it (including adding comments) etc, in a way a human would? What then? No, here I am not exploring a way to fool the code DNA checking, but rather trying to find out what the real problem is with the AI generated code? (Other than license issues, too many PRs etc)
I believe in linking over copy & paste, in particular when I want neither to quote the full FAQ nor editorialize by selective quoting. By reading the FAQ, people can form their own opinion on it.
They're just so information-dense and sprawl in scope.
Too many PRs wouldn't be a problem if they were easily digestible: But they often include these giant refactors with confusing changes that aren't elaborated.
The real underlying problem is with authors who do not understand the code they submit. If you cannot defend the PR, you shouldn't be submitting it.
The "blocking" happens on the side of the AI users. You like using AI. You are aware of this policy.
Will you submit an AI-generated pull request to OpenJDK? No? Voilà, you have successfully self-enforced the OpenJDK policy.
Or do you go to the trouble of finding an interesting issue to work on, get your agent to code it up, manually polish it to make it less AI-looking in case there are doubts, and then submit it? Yes? No. Why would you? To prove some kind of point, to yourself, that you can never disclose publicly? Most people have better things to do. Voilà, the policy is, again, self-enforced. Enjoy your day at the beach instead of trying to trick a project that is politely asking you not to trick it!
First time you're caught, you are no longer a project contributor and your deceptive conduct will be forwarded to all other major open source projects with warnings that your code cannot be trustworthy and is a well documented legal liability. How's that sit with you?
This is the firm whose debt is one level above junk and whose survival as a single unbroken corporate entity is fully predicated on OpenAI being able to make money from the data centres they (Oracle) are building for them, let alone simply paying for them.
I accept @jerf's explanation is the right one but this is an absolutely almighty signal that AI-first developers should heed. And someone should ask Altman about it on the record.
I don't disagree. But at the moment it is ~all major tech CEOs, right? Companies everywhere are saying "increasingly we don't write our own code". Out loud in front of their investors and customers. Even Oracle did.
But people at Oracle below the C suite don't even fart in public without lawyers signing off.
This is Oracle telling quite a lot of customers and partners of one of their most significant products that it doesn't trust AI code to be safe. Oracle, the company that is more exposed to the bubble bursting than basically anyone else apart from Coreweave.
This message could have been a lot shorter, could have said they were pausing accepting AI submissions until the intellectual property situation was clarified, but no — they said AI code can be unsafe and insecure and it's too risky to accept it. So a good question (given that Oracle are fucked if OpenAI even stumbles) is why?
That is a heck of a message to send, and it is visible enough. That is why I think developers (by which I mean individuals and their companies) whose focus is AI-generated code, which is almost everyone in public, should pay a bit of attention.
Oracle is just selling AI shovels. Of course it would have a hard time defending IP issues in slop code when it had famously sued Google for Java infringement.
Also, Oracle knows that it will be stronger with strong IP laws. Other companies will realize that fact soon.
So Java, which powers a sizeable chunk of the real-world since two decades now, without needing the help of LLMish sloppy-pasta, is going to continue to power the Real World [TM] with its language and JVM that have been created with tens of millions of human man-hours without LLMish sloppy-pasta?
I'm shocked.
I'm not only shocked: I also see there a delicious irony in the countless of LLMish sloppy-pasta code that's now running and going to be run on man-made JVMs.
> countless of LLMish sloppy-pasta code that's now running and going to be run on man-made JVMs.
Don’t worry, I think most LLMs, when starting a greenfield codebase, don’t reach for Java, so it may be a smaller amount of code affected than you feared.
They just have their panties in a bunch because that one guy on Youtube said they'd be the first domino to fall in the AIpocalypse. https://www.youtube.com/watch?v=py23zYn1GMw
It's not Oracle that issued the ban -- it doesn't have that authority. It's the OpenJDK Governing Board. (Of course the latter generally follows Oracle's lead.)
I would laugh for a week if the courts eventually found issues with using LLM content and forced companies to either publish their LLM generated code as public domain or they were forced to roll back their codebases to a pre-LLM state.
Probably won’t happen but clearly Oracle sees a potential for legal issues with LLM output.
Thing is public domain can be used any way you want. The Libre style licenses are specifically engineered to make the source available to the users of the source, no such clause exists in using public domain.
Not long ago it seemed as if AI Skynet is winning the war.
Now slowly, the Empire strikes back - not just Oracle, but more and more resist the tyranny of AI skynet slop.
I am upset that these corporations drove up the RAM prices still. They need to compensate the rest of mankind for this - after all the chip market is a de-facto monopoly. They should all be sued into nothingness, then new laws must enforce healthy and fair competition, without unfair players driving up the prices willy-nilly style. Absolute AI mafia here.
Oracle is not a software company, but a litigation company. It will be hard to sue people because LLMs generated code similar to some code copyrighted by Oracle if they themselves use LLMs internally to generate code.
Hilarious thing is, if I want a JDK, I'll ask Fable to write one, get Sol to review it and write tests for it, and it will be working by Monday morning. No need to get permission or anything else from Oracle. Building a complex product from many smaller, individually-testable components is exactly what LLMs are good at, and a Java SDK certainly qualifies.
And if I run out of tokens, well, that's OK too. K3 running on my own box will finish the job. I'll just have to wait another week, that's all.
If I want a JDK, I'll ask my package manager to download and install one, and it will be working a minute later. Why would you want to wait another week for something that already exists?
Please do this. I would love to see this timeline actually hold true. Production quality is the bar though. Not something that only works in a very narrow set of circumstances with a ton of caveats.
Probably it would get picked up by someone else (e.g. the Linux Foundation)? It's GPLv2-licensed, so it's not like the code is going to be risky for someone to fork
I don't think Oracle will die, but even entertaining the hypothetical I suspect that some other organization (e.g. Apache) would pick up and maintain a fork.
IBM, Red Hat, Microsoft, SAP, Amazon and others all work on the JDK. They would have to step it up to cover the loss of Oracle's contributions, but I am sure they could manage.
Regardless, your timeframe on Oracle's death seems way too soon.
Policies like this will result in the death of the branded software.
As we move forward it will be easier than ever to just maintain and keep your fork of software with the changes you want or need. No more approval, bureaucracy, or arguing. Just tell the AI agent want you want changed and you have it.
This will be used for huge things too. Like maybe you want a specific fork of Java that only supports for each iterators, goodby linters, hello compile time error.
You truly envision a future where every program is written in a custom programming language, for a custom operating system, for a single user who will now be in charge of understanding and maintaining it forever? That user being your grandma, your baker, your CEO?
Software as a list of requirements and that's it. The local LLM appliance everybody has taking in a document specifying hardware, interfaces, and requirements and spitting out software changeable locally via conversation with its users.
In the same way you have a cookbook with recipes to make dinner instead of ordering out.
> Software as a list of requirements and that's it. [...] a document specifying hardware, interfaces, and requirements [...]
For that, you'd want the list of requirements and hardware documentation to be written in a precise, formal language. That's no different than writing them in a programming language (though a declarative one, instead of the more common imperative ones).
I've in the past (way before LLMs existed) thought about automatically generating device drivers from hardware documentation. But besides the need for very precise documentation, hardware never works exactly as documented; a human-written device driver can avoid problematic areas (perhaps even by accident), while a computer-written device driver would end up exploiting every corner case of the documentation.
> For that, you'd want the list of requirements and hardware documentation to be written in a precise, formal language. That's no different than writing them in a programming language (though a declarative one, instead of the more common imperative ones).
From my perspective, this is a damning conclusion to the argument.
That being said, I can hear him asking Claude to generate a rebuttal as we speak.
Requirements ARE written in a precise, formal language. These days most people don't actually have any contact at all with real requirements though as practiced by professionals.
There is quite a bit of distance between the exactness of any human language and an sort of programming languages. When you have a language model loaded with software engineering best practices you do not need the exactness of a programming language to describe desired behavior.
Hardware documentation is indeed often lacking in plenty of ways but in a world where writing your own software through agents is commonplace, the hardware manufacturers (or the community) would make testing that documentation to find the problems an important part of hardware development.
Most people don't bake their own bread even if it's more approachable, and cheaper then vibecoding. Bread is just a recipe one may say. But in modern times have we ever witnessed disappearance of specialization? I don't think so.
> easier than ever to just maintain and keep your fork of software with the changes you want or need
I don't imagine this is practical or desirable for all situations. Good software is built from being battle tested by many users in many environments. Even with the advancements in AI tools, I don't imagine they'll become omnipotent anytime soon.
> No more approval, bureaucracy, or arguing
For software that can kill people or substantively affect someone’s life in a negative way, the bureaucracy is there for good reason. I don't think anyone should want someone at Phillips to vibe code the control software for an X-Ray machine or an employee at CrowdStrike vibe coding the next update before pushing it out to millions of machines.
We are forced to endure low-quality software because there is little or no accountability. I can only imagine what you propose would make an already poor situation worse.
I have my doubts about this. Brands are a about reputation, and reputation strongly affects responsibility when business decisions are made. If a manager decides to vibecode a solution which eventually fails, said manager will be punished. If instead a mainstream software is bought, and it fails - well, everybody has the same trouble around, right? It's not a personal mistake anymore. I suppose there are niches where branded software may give way, but I don't think it's gonna be a general trend.
This just reflects how absolutely clueless you are about the amount of attention to detail that the OpenJDK folks put into developing the language and ensuring that it works for all its users (which are serious users delivering actual value.) And I say this not even being a Java programmer myself, just an envious C++ dude watching from the sides.
> maintain and keep your fork of software with the changes you want or need
Then you'll have the same problem everyone who forks a piece of software ends up having, sooner or later: as the original evolves, keeping your fork up to date with the upstream changes becomes harder and harder. The bigger and more invasive the changes are, the harder synchronizing with newer releases become.
Someone brings this up on just about every AI-related thread. I think it's nonsense. Nobody wants to maintain a fork of any remotely complex software, not even with AI. And in a corporate setting, nobody wants to use your custom fork; they just want to use the standard software they already know with the quirks they've already learned.
This is far more likely to happen in a corporate setting with competent engineers who want to build/solve now versus relying on others. I've seen it 100% of the time with varying results.
Except. . . (accept)... SaaS solves the problem of needing one piece of software to communicate between multiple (many) users and/or other pieces of software.
Can't picture a functioning world where every piece of software is custom and requires factorial amount of AI comparisons and reviews to patch the API to communicate. In fact, it's impossible! There's not enough compute to handle a factorial explosion.
Given how much of the industry is SaaS that would be such a self own! Wow, fantastic, you can build all your software in house, zero dependencies. Wait, your users can do the same? And they don’t need to pay you anymore for any of your cool services because they just asked their agents to recreate your infra from scratch? Interesting, truly the future of humanity
> Wow, fantastic, you can build all your software in house, zero dependencies. Wait, your users can do the same? And they don’t need to pay you anymore for any of your cool services because they just asked their agents to recreate your infra from scratch?
The cherry on top is that OpenAI and Anthropic brainwashed your coworkers and your company's C-suite into uploading the entirety of the "proprietary" codebase onto their servers thousands of times per day over the last three years.
I think it's even more pervasive than that. Why bother forking software at all? At the point in which code generation is meaningfully trivialized, software becomes entirely disposable. Anything you want, have a model spin it up. You don't even need libraries, the model can just make everything in-situ, who cares? Why on earth would I ever want to use SQLite if I have access to a sufficiently advanced code generator which can generate me a similarly high quality database system, with the added benefit of conforming to whatever my problem domain is, conforming to whatever branch of database theory I want?
Even SaaS isn't safe. I don't even have to describe your product to my system, I just have to give it a harness with access to the interface and have it replicate it locally. Frankly you can probably already prompt for that.
The only thing holding this future back right now are pricing problems and code generation quality. Both of those barriers are constantly being knocked down. We might never arrive at that future, but it's definitely a higher probability than solving AGI's scaling issues, and would arrive much sooner for technical users.
> Why on earth would I ever want to use SQLite if I have access to a sufficiently advanced code generator which can generate me a similarly high quality database system
Because SQLite has 10k requirements that wouldn't even cross your mind to write down, but 80% of which are useful to you.
The nice thing about natural language is that nesting semantic layers is free and arbitrary, and far more tractable than in a formal grammar. Every natural language is like coherentist ω-order logic. Effectively, I don't have to write the 10k requirements. I only need to provide a sufficient metatheory that can be extrapolatable to those 10k requirements, and that can include embedded theory I did not write myself but am familiar with enough to invoke, as well as refinement criteria ranging from the fuzzy to the explicit with priority weighting parameters to describe the shape in which I want the search space pruned.
This isn't anything new or particularly interesting. It's the entire basis upon which ILP demonstrated generality. A metatheory to synthesize 10 trillion rules isn't even scratching the surface of what you can reasonably do. The key was finding out the tractable semantics for actually computing it in reasonable amount of time, which right now is looking decidedly like informal semantics was the answer the whole time.
I accept your concession. The humiliation of irrationally committed foundationalists has been a long time coming, so it's good you're trying to get ahead of the curve.
>Why on earth would I ever want to use SQLite if I have access to a sufficiently advanced code generator which can generate me a similarly high quality database system
https://www.youtube.com/watch?v=V_qzqY1bb7I your sufficiently advanced code generator may generate you a high quality database system for some measure of quality, but it will not have SQLite's reliability over the extremely long tail of edge cases proven through its testing and use in real life
Then you've failed the criteria of sufficiently advanced. It's perfectly fine to cast doubt we'll see scaling to this generalization, but you're not casting doubt you're outright rejecting the premise in-confidence. It betrays that you have no idea what you're talking about. May I see your quantification of this long tail? Do you even know how to formalize the mapping from n-bit precision of weights and/or activations to the standard deviation of a transformer's output distribution, such that we could decide whether the long tail of a given behavior is unreachable? Something tells me that no, you don't know how to do that in the slightest. So what drives you to speak with such confidence?
That's before we get into the entire non-linearity of agentic systems introducing massive decidability problems on this in the first place. A little bit of epistemic humility please.
It's more like that movie with Stephen King where the cars and other machines turn actively evil. Hilarious movie too, not great but hilarious.
Maybe so, but perhaps the most successful part of the AI marketing pitch has been exploiting management's hatred of labor (and vice versa).
A significant motivator for a lot of the nonsensical AI layoffs and initiatives over the last three years has been that it's a great opportunity for management to get ill on their slaves.
Tech labor got a little too big for their britches during the hiring spree of 2021, and AI was a great opportunity to take them down a peg, even if it offered little in the way of ROI.
Don't underestimate the power of the desire to keep one's job to cause a large organization to behave towards its own self-perpetuation despite the moral lines that must be crossed by individuals to do so.
Lots!
> Don't underestimate the power of the desire to keep one's job to cause a large organization to behave towards its own self-perpetuation despite the moral lines that must be crossed by individuals to do so.
I don't. I don't put anything past people.
In other words, Larry Ellison is going to do what Larry is going to do, and there's no use wondering why.
Usually, that's to make money and sue people, at any expense. It's in his nature.
https://en.wikipedia.org/wiki/The_Scorpion_and_the_Frog
The lawnmower exists, you might disagree, but it’s not your lawnmower, you can’t uncreate it. But you can and should take care never to put your hand near it.
Lessons:
- The only way to constrain what the lawnmower does, is make sure what do desire is enforced by law (physics)
- A reminder, the lawnmower will chop your hand off and think nothing of it
- The lawnmower is not "evil" but if the laws that constrain it allow for evil behavior, it may do "evil" things.
If that's a reference to Thaler v. Perlmutter, the only thing that's been established is that an LLM can't be considered an author under the Copyright Act, only a human being can. It says nothing about the consequences of a human claiming authorship of LLM-generated code, which would be relevant here.
If you write a prompt and one-shot a problem and share the source code, that source code is probably not covered by copyright.
If you substantially edit or modify the generated code you would own the copyright.
It's like with a camera. If I set a camera and carefully aim it and somehow trigger the shutter then make adjustments in Photoshop, I own the copyright on that image.
If I stick a Flock camera on a pole somewhere and post the live output, there's been no meaningful human creative involvement in producing those images and so nobody can claim copyright on them.
I don't like this idea that llm code can't be owned by a human, copyrighted. It's just code.
I think your last example with flock camera is relevant here - I can take a picture of a public football as a reporter or something (or a fan I guess) and I can copyright and sell that picture. Newspapers do it every day.
So if I stand on a street corner and take a pic, it's copyrightable. If I take a pic using a flock camera it should also be copyrightable, just like if my nest camera at home takes a pic of something, I can use that.
I guess you are saying "someone else owns the flock camera" so you don't get to own pictures. What if I buy the flock-like camera and put it up, I should own that.
Thaler v. Perlmutter stands for a much narrower proposition and at any rate is not binding nationally, SCOTUS having denied certiorari.
> Based on an analysis of copyright law and policy, informed by the many thoughtful comments in response to our NOI, the Office makes the following conclusions and recommendations: > • Questions of copyrightability and AI can be resolved pursuant to existing law, without the need for legislative change. > • The use of AI tools to assist rather than stand in for human creativity does not affect the availability of copyright protection for the output. > • Copyright protects the original expression in a work created by a human author, even if the work also includes AI-generated material. > • Copyright does not extend to purely AI-generated material, or material where there is insufficient human control over the expressive elements. > • Whether human contributions to AI-generated outputs are sufficient to constitute authorship must be analyzed on a case-by-case basis. > • Based on the functioning of current generally available technology, prompts do not alone provide sufficient control. > • Human authors are entitled to copyright in their works of authorship that are perceptible in AI-generated outputs, as well as the creative selection, coordination, or arrangement of material in the outputs, or creative modifications of the outputs. > • The case has not been made for additional copyright or sui generis protection for AI-generated content. > The Office will continue to monitor technological and legal developments to determine whether any of these conclusions should be revisited. It will also provide ongoing assistance to the public, including through additional registration guidance and an update to the Compendium of U.S. Copyright Office Practices.
Congress or the courts could, of course, override the stance of the copyright office, but I think it would be highly unusual for them to do so (particularly for something like this). It would however be a lot better if congress just stepped in and said no outright, but until then this will have to do.
[0]: https://www.copyright.gov/ai
Only Congress and the courts do. Copyright exists from the moment a work is created, and does not need to be registered with the copyright office.
The law isn't that complicated; if a work was created with a human being with intent, it's probably eligible for copyright protections.
As long as you can convince a court that you did this, the tools you used are not relevant. The vast majority of LLM art falls in this bucket.
> Whether human contributions to AI-generated outputs are sufficient to constitute authorship must be analyzed on a case-by-case basis
It says a plain prompt is not enough but that is not the reality of real software development. People aren't one-shotting complex business apps. The vast majority of software development will trivially pass that bar and end up in the "requires case by case analysis".
The sibling comment lays this out and my original comment above is based on exactly the same link.
[1] https://www.cio.com/article/4125103/oracle-may-slash-up-to-3...
They are trained on a narrow set of data and don't really understand the real world.
If you let them run wild with no supervision they'll turn your company into slop.
Someone needs to be there to reign them in, asking the all-important questions like "is suing all of our customers and making them angry REALLY the best option?" (to which they will reply, "You're right to push back on this").
This is typically the role of the CEO, however, as we know, most CEOs of large successful companies are too busy to actually do that. They're mostly training Brazilian Jiu Jitsu, shitposting on their own social media platform, trying to manipulate international politics, or helping run their family nonprofit.
This is why I believe that legal departments need to be demoted. The legal department should not report to the CEO, they should report to a new role that is above both PR and legal. And that person's job should be to force legal and public relations (which we know are natural enemies) to work together. Every press release goes through legal now, and it's only logical that ever legal action should go through public relations review as well.
The fact that public relations at most large companies has atrophied from disuse in our public-equity-owned unicorporate cooperation-over-competition chaebol/zaibatsu/conglomerate world is a problem for another day.
https://www.theregister.com/ai-and-ml/2026/08/03/as-larry-el...
The register article is about this post:
https://openjdk.org/legal/ai
It is 'OpenJDK Interim Policy on Generative AI' and their lawyers are writing the final version, according to this page.
It sounds like a sensible action, given past scars around Java and copyright, plus this is from a big old corp.
That said I personally don't expect that final proposal will end up any better.
How many of these were self-inflicted?
> Contributions in the OpenJDK Community must not include content generated, in part or in full, by large language models
So this likely falls more into the category of the inability of the core maintainers to manage the voluminous submissions coming from community than some broad ban of use in AI to develop it at all.
Especially for a project that runs to many major businesses, this could pose a massive risk.
Seems like a better way to do this than ban all AI generated code, but it's probably a matter where they're far more concerned about their own inconvenience than someone else's.
I’m sure someone could still just prompt their way through but it’s a decent soft gate IMO.
Humans still need to review code for taste, making sure AI is writing sensible, well organized output. That's a core "AI skill" for now, at least until it gets better...
in any of those cases there's no reason to get swamped by cheap PRs for now
I think for Java specifically, it's also very much: which prompts make sense to write. Java has had a storied history of features that made future development hard. That's resulted in a culture where they like to think quite deeply about how to add a feature BEFORE they sanction any sort of programming.
The same problems that bedevil AI-written PRs here bedevil AI-written PRs at my place of work.
I'm sure it'll get better eventually, maybe, but something something Pareto principle.
>I'm sure it'll get better eventually, maybe
Why would it get better?
Google “Oracle org chart meme” and look at image results, only it’s not a meme.
Selling it is one thing. Having to use it one's self is quite another.
Do as Larry does --- not as Larry claims to do.
I would short his stock but it has already lost half it's value over the past year. And his credit rating is one notch above junk.
AI is going to make fools out of a lot of billionaires like Larry.
Even the biggest institutional AI investors have to ban their contributors from spamming them with AI generated slop.
Shitposting, the reasons are very clear and explicit: The risks of having legal problems are very clear.
Google for example GEMA vs. OpenAI.
"6 Is it okay to continue using the spell-checking, grammar-checking, auto-completion, and refactoring features in my editor or IDE?
Yes, so long as they are not based on large language models or similar deep-learning systems."
code is a liability, and they likely have more to lose than gain by allowing AI contribution.
java never had that phase. If anything it had a full binary class (not even source, e.g. long and int are not compatible on binary level) compatibility. Generally you can take an application from '98 and run it nowadays.
It's only recent changes (jigsaw in java9 mostly) that were made them to drop some of that part.
It's shocking given Oracle's AI spending spree over the last couple of years.
If you know how to work with it it's great, but if you use it indiscriminately it does more harm than good.
The biggest use of Java currently is Android, and Google is on a path to migrate to Fuchsia eventually.
The second biggest use is Apache Spark/Kafka, but with LLMs now, you can pretty much re implement all of that functionality in pure C.
They just want a legal angle, since this is how they make most of their money.
Spark is written in Scala, precisely because distributed systems are best modelled as a set of pure functions with minimal references to state. This is also why part of the reason why it's ascending successor, Polars Cloud, is written in a functional language, Rust, rather than C.
Android development is also increasingly being monopolized by Kotlin, not Java.
https://en.wikipedia.org/wiki/OpenJDK
The "limited ROI on AI investment" articles will continue to percolate slowly into the brains of the LinkedIn hive-mind until we hit a tipping point, and then we'll finally shut up about how a handy dev tool with some decent use-cases is the dawning of the singularity that will replace all white collar labor and get back to actually building business value.
I’m not saying it’s good for everything, but we’ve gone very far in terms of capabilities in the last 3 years. Thinking otherwise will make me question others’ experience on how much they’ve used it so far.
it would be more convincing if you had concrete examples of technical merit and quality/speed improvements that worked for you or your team that justify going all-in
I manage several teams of developers who use them every day professionally and use them for personal projects privately. Just last week, at the prompting of said devs, we had a working agreement conversation about curtailing the use of AI in our codebases because of rapid erosion of our teams' ability to operate, update and maintain codebases that had started to spill over with slop.
We have had multiple incidents of credential leakage, integration tests wiping live databases, comically broken code that passed vibe-written tests, documentation and code comments that were hallucinated and/or fake, and most importantly developers saying "we no longer know how this code works but it's massively bloated and unreadable and we can't tell you with a straight face that we can maintain it or fix it if it breaks." We have seen a flood of vibe-PRs from engineering adjacent teams that suddenly think they can code shipping prototypes into production that do not work do not scale and cannot be maintained. I am personally writing the tickets to decom one of those today. Which is great, I love telling business "the progress that was reported to you was a lie, this shit never worked, don't shoot the messenger but also don't let this happen again."
I embrace GenAI as a productivity tool for people who know what they are doing. It's a +10-15% velocity boost. That's great! That's a big deal, devs are expensive, and that might push some kinds of business model over the threshold into viability. That's great!
It is not, however, transforming the profession as I know it, it is rather making my job harder and less pleasant and it is making my leadership dumber by the second.
Absolutely no comment on vibe business decisions / vibe OKRs / slop reports or the host of other garbage that has started to creep into professional life. I have had to have some very uncomfortably direct conversations with peers in leadership about using complete bullshit to make decisions, and it is very, very frustrating. Do you know how hard it is to convince someone that metrics their bot hallucinated don't exist and would be meaningless if they did? You can't convince someone of something they are incentivized to not understand. It's been very eye-opening in terms of who I can trust to actually make sense when it matters. I'm grateful for the clarity.
Meanwhile we are rapidly losing brainshare from the top because our principal/staff engineers are pissed off and have the bankroll to just leave. We aren't hiring and training younger engineers to keep the talent pipeline moving. Which boy howdy is THAT going to cost us unbelievable sums of dollars to fix in the medium-term future.
I am in the uncomfortable role of trying to make the best of this but it would be a metric ton easier if the narrative from the c-suite aligned with reality in any meaningful way.
</rant>
when i brought this up with my manager they just said "you need to engineer a better harness" and "aren't you cultivating your agents.md file? thats probably your problem"
which is to say, apparently we're holding it wrong...
To anyone reading this: If you couldn't see this coming three years ago, you don't deserve your job.
> We have seen a flood of vibe-PRs from engineering adjacent teams that suddenly think they can code shipping prototypes into production that do not work do not scale and cannot be maintained.
What a nightmare. Never forget that AI is for idiots.
Linux's LLM policy allows AI-generated code because the project was never vulnerable to this DoS attack in the first place. They kept the social defense they've had for decades.
The killzone here is Github culture, where people decided it was normal to accept code from anonymous randoms with anime avatars. They're doomed.
I haven't written a line of code myself in 6 months, but the point is that _you shouldn't be able to tell_
What I tell people at work: Using AI is good. AI can help you do things that you otherwise wouldn't have. It shouldn't be a crutch for thinking.
In that sense, people shouldn't be able to tell that you're using AI unless the tell is that it's _higher quality_ than if you had implemented it by hand.
A good example here is a well-written document that has a _ton_ of deep research behind it. Or code that has extensive tests that would have taken too long to write by hand for the task at hand.
It's bad when it's just "do this thing and post a PR" but I write my code with AI, look at it as a reviewer, offer suggestions, put those into my steering if needed, and I refine it. The way I see it, I'm the first reviewer on everything now before passing it off to another human for review.
There have been points where having AI rewrite something was slower than me doing it, but I'm already in the harness. The cost of waiting is almost zero. What stops me from contributing to the JVM using AI written code that I understand and spent time manicuring? Can a human really tell that it's AI written?
It would be interesting to see how this effects the copyleft Licences with contributors are using AI for the PRs
Which recent verdict?
> It would be interesting to see how this effects the copyleft Licences with contributors are using AI for the PRs
I know Linux and GCC have been diligent about tagging and tracking LLM based contributions. In the worst case they can chuck it all out and handwrite it back.
There is this old one around contents like images and all, the ripple affect is pretty much everywhere.
Its sort of coupled with the recent penalty of $1.5B on Anthropic. The catch 22 is that some portion of the LLM training data can be classified as IP theft. Even though Anthropic has been fined the data still exists and can be used by LLM to generate code for you. So if you are claiming something as an IP and it has stolen part in it then it leaves you in a hard place.
Language translations may save you in some cases, though the whole definition of cleanroom has been in debate recently too where people are trying to rewrite opensource/famous libraries in different language and claiming IP rights over them.
Settlement not penalty.
Anthropic will have judged the benefits of the settlement, not just the headline cost. It could have been a strategic move by Anthropic: we can't know without information we don't have. https://news.ycombinator.com/item?id=49014389 1.5B looks like ~2% of funding/income.
Secondly the future is still not here yet, the people who came forward to sue are mostly in the category of book publishers/authors. The tech companies are are not actively searching for copyright thefts as of yet, however I am sure its just a matter of time when the big blobs of codes get rediscovered specially in case of any publicly visible code
Other copyright lawsuits against other major companies are happening.
If a similar lawsuit costs OpenAI more than 1.5B then perhaps Anthropic is better off in their competitive race?
> the people who came forward to sue are mostly in the category of book publishers/authors
Irrelevant. The financially savvy parties are the lawfirm L.L.P.s trying to win money for themselves.
Refusing to use AI honestly seems more like vanity to me. Like "no machine could ever do what I do".
That said I would not necessarily accuse people who don't want to use AI of vanity - there are good reasons not to want to use it - but if someone else did it I'd find it easier to understand.
One also assumes the people maintaining OpenJDK have had their workload increase to an unmanageable level, like a lot of other free software projects and one thing I'm sure everyone can agree on is that Oracle certainly won't want to pay anyone more or hire more people to deal with that.
A lot of people (including the Register[0]) are pointing out that Oracle leadership are gung-ho about using LLMs for everything, and this seems to go against that. It makes sense to question this from a journalistic angle -- the executives are obviously full of shit and people would do well to remember that the next time one of them opens their mouth. But pointing at the apparent contradiction -- different rules for internal projects vs. open ones -- doesn't seem particularly meaningful on its own:
I don't think the CEO/CTO raving about LLMs should be taken as firm statements about how they actually operate internally. I'm surprised that this does not seem to be the default case. Among other things, Oracle stands to profit from greater adoption of LLM tools.
It would be unrealistic/unreasonable to expect their employees/contractors working on internal projects to be held to the same standard/guidelines/rules as developers contributing to a free software project. This applies either way, whichever side (internal/open) has the worse deal.
I don't know what the rules are for their internal teams. As far as I know, I'm not alone in that. Oracle also don't need to post anything publicly to change those rules.
[0] https://www.theregister.com/ai-and-ml/2026/08/03/as-larry-el...
> If I use a generative AI tool to create 100 lines of code, and then edit ten of those lines myself, may I contribute the result?
> No. Your contribution would still include, in part, AI-generated code.
I totally agree with you on this! The engineer is still actively engaging while getting the performance gains of not having to type out functions. The Engineer is still in charge vs agentic "engineering" a model + harness can spit out whatever and the engineer is left to review tons and tons of code
sips tea
There is also the approach of Microsoft putting AI all over the place on .NET, and CoPilot driven development all over the place.
What if someone generates code with AI and then goes into the IDE and then bathes it, dresses it (including adding comments) etc, in a way a human would? What then? No, here I am not exploring a way to fool the code DNA checking, but rather trying to find out what the real problem is with the AI generated code? (Other than license issues, too many PRs etc)
Too many PRs wouldn't be a problem if they were easily digestible: But they often include these giant refactors with confusing changes that aren't elaborated.
The real underlying problem is with authors who do not understand the code they submit. If you cannot defend the PR, you shouldn't be submitting it.
Will you submit an AI-generated pull request to OpenJDK? No? Voilà, you have successfully self-enforced the OpenJDK policy.
Or do you go to the trouble of finding an interesting issue to work on, get your agent to code it up, manually polish it to make it less AI-looking in case there are doubts, and then submit it? Yes? No. Why would you? To prove some kind of point, to yourself, that you can never disclose publicly? Most people have better things to do. Voilà, the policy is, again, self-enforced. Enjoy your day at the beach instead of trying to trick a project that is politely asking you not to trick it!
And if you catch somebody submitting code they can't explain, you don't know them anymore.
It's really simple. Open source has always had a social layer. Github culture tries to eliminate it, and that's the source of this vulnerability.
I accept @jerf's explanation is the right one but this is an absolutely almighty signal that AI-first developers should heed. And someone should ask Altman about it on the record.
The people you refer to are delusional idiots and should be treated as such.
But people at Oracle below the C suite don't even fart in public without lawyers signing off.
This is Oracle telling quite a lot of customers and partners of one of their most significant products that it doesn't trust AI code to be safe. Oracle, the company that is more exposed to the bubble bursting than basically anyone else apart from Coreweave.
This message could have been a lot shorter, could have said they were pausing accepting AI submissions until the intellectual property situation was clarified, but no — they said AI code can be unsafe and insecure and it's too risky to accept it. So a good question (given that Oracle are fucked if OpenAI even stumbles) is why?
That is a heck of a message to send, and it is visible enough. That is why I think developers (by which I mean individuals and their companies) whose focus is AI-generated code, which is almost everyone in public, should pay a bit of attention.
Also, Oracle knows that it will be stronger with strong IP laws. Other companies will realize that fact soon.
I'm shocked.
I'm not only shocked: I also see there a delicious irony in the countless of LLMish sloppy-pasta code that's now running and going to be run on man-made JVMs.
Don’t worry, I think most LLMs, when starting a greenfield codebase, don’t reach for Java, so it may be a smaller amount of code affected than you feared.
Prompt: “Top language pick for an Android app? Respond with only the language.”
Responses (admittedly via the aichat CLI, not an agent harness; and temp=0):
Kimi K3: Kotlin
GPT 5.6 Sol: Kotlin
Claude Fable 5: Kotlin
DeepSeek v4 Flash 0731: Kotlin
Are there any other “inherently” heavily JVM-biased domains?
I think even in Minecraft game mods Kotlin is possible nowadays…
https://openjdk.org/legal/ai
That Oracle's policies over its internal code base are different is irrelevant.
Probably won’t happen but clearly Oracle sees a potential for legal issues with LLM output.
Now slowly, the Empire strikes back - not just Oracle, but more and more resist the tyranny of AI skynet slop.
I am upset that these corporations drove up the RAM prices still. They need to compensate the rest of mankind for this - after all the chip market is a de-facto monopoly. They should all be sued into nothingness, then new laws must enforce healthy and fair competition, without unfair players driving up the prices willy-nilly style. Absolute AI mafia here.
And if I run out of tokens, well, that's OK too. K3 running on my own box will finish the job. I'll just have to wait another week, that's all.
Regardless, your timeframe on Oracle's death seems way too soon.
As we move forward it will be easier than ever to just maintain and keep your fork of software with the changes you want or need. No more approval, bureaucracy, or arguing. Just tell the AI agent want you want changed and you have it.
This will be used for huge things too. Like maybe you want a specific fork of Java that only supports for each iterators, goodby linters, hello compile time error.
Software as a list of requirements and that's it. The local LLM appliance everybody has taking in a document specifying hardware, interfaces, and requirements and spitting out software changeable locally via conversation with its users.
In the same way you have a cookbook with recipes to make dinner instead of ordering out.
For that, you'd want the list of requirements and hardware documentation to be written in a precise, formal language. That's no different than writing them in a programming language (though a declarative one, instead of the more common imperative ones).
I've in the past (way before LLMs existed) thought about automatically generating device drivers from hardware documentation. But besides the need for very precise documentation, hardware never works exactly as documented; a human-written device driver can avoid problematic areas (perhaps even by accident), while a computer-written device driver would end up exploiting every corner case of the documentation.
From my perspective, this is a damning conclusion to the argument.
That being said, I can hear him asking Claude to generate a rebuttal as we speak.
There is quite a bit of distance between the exactness of any human language and an sort of programming languages. When you have a language model loaded with software engineering best practices you do not need the exactness of a programming language to describe desired behavior.
Hardware documentation is indeed often lacking in plenty of ways but in a world where writing your own software through agents is commonplace, the hardware manufacturers (or the community) would make testing that documentation to find the problems an important part of hardware development.
I don't imagine this is practical or desirable for all situations. Good software is built from being battle tested by many users in many environments. Even with the advancements in AI tools, I don't imagine they'll become omnipotent anytime soon.
> No more approval, bureaucracy, or arguing
For software that can kill people or substantively affect someone’s life in a negative way, the bureaucracy is there for good reason. I don't think anyone should want someone at Phillips to vibe code the control software for an X-Ray machine or an employee at CrowdStrike vibe coding the next update before pushing it out to millions of machines.
We are forced to endure low-quality software because there is little or no accountability. I can only imagine what you propose would make an already poor situation worse.
Then you'll have the same problem everyone who forks a piece of software ends up having, sooner or later: as the original evolves, keeping your fork up to date with the upstream changes becomes harder and harder. The bigger and more invasive the changes are, the harder synchronizing with newer releases become.
Can't picture a functioning world where every piece of software is custom and requires factorial amount of AI comparisons and reviews to patch the API to communicate. In fact, it's impossible! There's not enough compute to handle a factorial explosion.
I really doubt SaaS going anywhere.
The cherry on top is that OpenAI and Anthropic brainwashed your coworkers and your company's C-suite into uploading the entirety of the "proprietary" codebase onto their servers thousands of times per day over the last three years.
Even SaaS isn't safe. I don't even have to describe your product to my system, I just have to give it a harness with access to the interface and have it replicate it locally. Frankly you can probably already prompt for that.
The only thing holding this future back right now are pricing problems and code generation quality. Both of those barriers are constantly being knocked down. We might never arrive at that future, but it's definitely a higher probability than solving AGI's scaling issues, and would arrive much sooner for technical users.
Because SQLite has 10k requirements that wouldn't even cross your mind to write down, but 80% of which are useful to you.
This isn't anything new or particularly interesting. It's the entire basis upon which ILP demonstrated generality. A metatheory to synthesize 10 trillion rules isn't even scratching the surface of what you can reasonably do. The key was finding out the tractable semantics for actually computing it in reasonable amount of time, which right now is looking decidedly like informal semantics was the answer the whole time.
https://www.youtube.com/watch?v=V_qzqY1bb7I your sufficiently advanced code generator may generate you a high quality database system for some measure of quality, but it will not have SQLite's reliability over the extremely long tail of edge cases proven through its testing and use in real life
That's before we get into the entire non-linearity of agentic systems introducing massive decidability problems on this in the first place. A little bit of epistemic humility please.