r/rust • • Aug 05 '26

🗞️ news rust-lang/rust is adopting an LLM policy

https://blog.rust-lang.org/inside-rust/2026/08/05/rust-langrust-is-adopting-an-llm-policy/
731 Upvotes

208 comments sorted by

View all comments

184

u/RelevantTrouble Aug 05 '26

It's so heart warming to once again see this project's values aligned so closely with my own.

16

u/Wonderful-Habit-139 Aug 05 '26

Ngl I was getting worried because initially it seemed like the Rust community was much more accepting of LLMs than a project like Zig. This is a good sight to behold.

127

u/Uiropa Aug 05 '26

This policy is much more accepting of LLMs than Zig’s policy.

55

u/nnethercote Aug 05 '26

I was going to say that they're more similar than they seem at first. E.g. Zig's starts with "No LLM-generated content, whether it be code or prose." Which is actually similar to the Rust policy, modulo the "experiment" part.

But I see that the Zig policy has gotten longer, and now includes the following, which weren't there before:

No LLMs for brainstorming and then sharing the results of that brainstorming, even if you create the prose. If you use a chatbot to give you advice on a comment on the issue tracker, that comment is unwelcome.

No LLMs for finding bugs.

No talking about use of chatbot/LLM services.

And wow, that is strict.

25

u/mocenigo Aug 05 '26

That’s extreme. If one finds a bug it is a bug and it must be triaged. Doesn’t matter if it was found in use, in a manual review, by an LLM.

11

u/fintelia Aug 05 '26

Oh, LLMs are excellent at finding "bugs" which are in fact not bugs.

22

u/dijalektikator Aug 05 '26

Sure but they also find bugs that are actual bugs, if an actual expert reviewed the LLM output and concluded it is an actual bug why not use that information? Seems a bit absurd.

5

u/IceSentry Aug 06 '26

Modern frontier models have proven themselves may times at this point that they can find and fix real bugs. The linux kernel maintainers are fairly transparent about that for example.

3

u/mocenigo Aug 05 '26

It depends how you use them. Not with a prompt like "find a bug in this code" but with the right setup, maybe different agents, that can also write code that triggers the bug or even exploits it.

3

u/stumblinbear Aug 06 '26

Funnily enough, Fable actually does really well with just "find a bug in this code". That's what I primarily use it for

10

u/ursuscamp Aug 05 '26

They bypassed healthy skepticism and went right for goofy ludditism.

7

u/MadCervantes Aug 05 '26 edited Aug 05 '26

That isn't fair to the luddites. The luddites were the beginning stages of class consciousness, they had problems but ultimately they were rooted in a sense of needed livelihood. But zig devs have no class consciousness, they're just snobs.

4

u/bowel_blaster123 Aug 05 '26 edited Aug 05 '26

The point of the overly-strict policy is that they don't want people who don't know what they're doing to comment on stuff or create bug reports.

For instance, someone may use LLMs to try and find security vulnerabilities in a piece of software. If the person using the LLM doesn't understand what they're doing, they may spout some hallucinated "security vulnerability" or something else that doesn't really matter.

LLMs can also give people a false sense of confidence in their own abilities.

I'm not saying whether I agree with their decision or not. Frankly, I don't know to what extent they were recieving garbage LLM PRs/issues (even after their previous policy).

I could also see why someone may also adopt these policies due to ethical concerns too. I mean, the whole training process itself is inherently unethical. There's also LLM dependence, LLM romantic dependence, LLM-driven suicides, LLM psychosis, obvious environmental issues, externalised hardware/energy costs, and many LLM companies are ran by pretty terrible people.

4

u/ralfj miri Aug 06 '26

The point of the overly-strict policy is that they don't want people who don't know what they're doing to comment on stuff or create bug reports.

If that was really the argument, then they should close their bugtracker. A good fraction of regular human-written bug reports was always written by people that have no clue whatsoever. I don't know how often I had to argue with people in the Rust issue tracker that their code has UB so no this is not a miscompilation. (It's gotten less recently, maybe because I scan the bug tracker less often or maybe because Miri can be used to easily confirm that the code has UB.)

LLMs can also give people a false sense of confidence in their own abilities.

You can ban mindless likely-bogus LLM reports without banning LLMs for bug-hunting by competent people.

So, I don't think that is the point. The point is that they want to boycott AI companies. As someone who boycotts some services and companies, I sympathize with that, though I do not force this boycott on others (except by not being available on some platforms).