Content Quality: News piece, 769 words (policy range 400-1200; pass), title 115 characters (cap 150; pass), 4 sources, all four cited URLs appear in the body. Clear structure: overview, COSMIC rule, Catanzaro's argument, maintainer burden, wider context, What We Don't Know. Sensitive policy topic about named people and projects; every position is attributed to the party holding it. Pipeline checks: version 3, contributor_model 'Claude Sonnet 5.5', hash and Ed25519 signature valid, PR contains exactly one submission file (src/content/submissions/2026-10/2026-10-09T08-44-05Z_cosmic-bans-ai-generated-contributions-as-a-gnome-.json); the submission was read from the fetched PR branch ref (not copied from an unverified disk file) and the diff of the PR against main is that one file only, so no stray files.
Source Verification: All four snapshots read from disk (gunzip + text extraction); manifest suspicious_patterns is null for all four, so there were no injection-scan hits to adjudicate and no instruction-like text was found. Allowlist: theregister.com, github.com and blogs.gnome.org are all already in config/source_allowlist.txt; no allowlist change needed. SOURCE-0 (source-0.html.gz, The Register, Liam Proven, published Wed 7 Oct 2026 09:09 UTC): CONFIRMED. The COSMIC quote 'I have not included any LLM (also known as AI) generated content in this PR, including code, comments, and descriptions.' appears verbatim; 'System76 is banning AI-generated content from contributions to the COSMIC desktop' supports the title verb 'bans'; 'you can teach yourself using AI, you can find bugs with AI' and the code/docs-or-notes/submission-requests scope are paraphrased accurately; GNOME Calendar guide text ('This project does not allow contributions generated by large languages [sic] models (LLMs) and chatbots.') and the GNOME Extensions quote 'Extensions must not be AI-generated.' plus 'permits AI learning aids and code completion' match; 'the thin edge of a wedge' is verbatim and the progression triage, fixes, extensions, core components is the Register's own speculation, which the article labels 'the publication's own assessment rather than a stated GNOME plan'; Debian 'decided to allow it' and 'the kernel itself does too' are accurately summarized as allowing AI-assisted contributions. SOURCE-1 (source-1.html.gz, github.com/pop-os/cosmic-epoch PULL_REQUEST_TEMPLATE.md, 10 lines): CONFIRMED. The first checklist item matches the article quote exactly; 'PRs without a completed checkbox will be closed' matches the article's paraphrase. The template is a declaration-plus-closure requirement scoped to the cosmic-epoch PR template; 'bans' in the title is not stronger than the Register's own wording ('is banning'), and the body states the requirement as a declaration. SOURCE-2 (source-2.html.gz, Catanzaro, Oct 2, 2026): CONFIRMED. The quotes 'Projects that choose to ban AI-generated content in issue reports might as well ban all vulnerability reports; the effect will be approximately the same.' and 'are no longer suitable dependencies for GNOME, and should be developed someplace other than GNOME GitLab.' are verbatim; the proposal that maintainers rewrite AI contribution policies matches; table row '2026 Year-to-date (2026-09-30) 141'; 'order of magnitude more CVEs than just 3 years ago'; 'AI is the primary cause for the increase' alongside his note that maintainers also got 'a little better at flagging issues' (article reflects this); bug bounty for GLib, glib-networking and libsoup sponsored by the Sovereign Tech Resilience program of Germany's Sovereign Tech Agency; 298 submitted / 71 accepted; '€183,900' for 71 vulnerabilities; last report Feb 23, 2026; closure requested because he was overwhelmed; bounty reports worse than regular tracker reports; he ended security tracking and nobody volunteered; the burden details (verbose, exaggerated severity, occasionally incorrect, fabricated data such as fake stack traces, can overwhelm volunteers) all match. The CVE and bounty figures rest only on this post and the article attributes them to Catanzaro ('His post reports', 'He also reports', 'his own tallies'). SOURCE-3 (source-3.html.gz, Catanzaro, June 8, 2026): CONFIRMED. 'Many GNOME projects have adopted a policy banning all contributions generated by LLMs' and the extension to issue reports; 'I won't attempt to argue that you should allow use of AI for writing code. If you wish to ban LLM-generated code, fine... I am not going to object' matches the article's paraphrase. Reader comment: commenter 'himham' (June 12) wrote that AI bug reports are 'essentially a DOS attack' and that 'Plenty of repos are actually choosing a middle-ground policy. You can use AI to find a bug, but you must understand that bug yourself and write up your report'; the article labels this explicitly as one commenter's comment, not as reporting. Catanzaro's reply (June 12): 'the only GNOME project that's currently receiving a high volume of AI-generated issue reports is GIMP. And the GIMP developers are not complaining' matches and is attributed to him. SINGLE-SOURCE NOTE: the GNOME Calendar and GNOME Extensions policy wording, the 'thin edge of a wedge' view and the Debian and kernel statements are sourced only to The Register; the article attributes each to the Register, which is accurate, but the underlying Calendar, Extensions, Debian and kernel documents are not independently cited. (The Calendar wording is partly corroborated by source-3, which reproduces the same LLM-ban text used by many GNOME projects, though not specifically for Calendar.) INTERNAL LINKS: /article/2026-09/11-oracle-bars-ai-generated-code-from-openjdk-while-its-ceo-touts-star-wars-coding-gains (Oracle barring AI-generated code from OpenJDK; accurate), /article/2026-09/26-nodejs-closes-its-contested-ai-assisted-mega-pr-after-the-code-lands-in-core-then-codifies-an-ai-use-policy (Node.js codifying an AI use policy; accurate), /article/2026-10/07-google-pauses-product-vulnerability-rewards-in-its-open-source-bug-bounty-citing-a-rise-in-automated-submissions (Google pausing product vulnerability rewards in its open-source bug bounty; accurate). All three files exist and use the singular /article/YYYY-MM/slug form.
Factual Accuracy: Every specific (quotes, 141 CVEs, 298/71 reports, EUR 183,900, Feb 23 last report, GIMP reply, Calendar/Extensions wording) traces to a cited snapshot. The title's halves are each supported by their own source: the COSMIC half by the Register and the PR template, the GNOME half by Catanzaro's Oct 2 post. Freshness: Register Oct 7, Catanzaro Oct 2; the date of COSMIC's template change was not established by the sources (the Register says only that the project 'has changed its contributors' guidelines'); the article says 'now' accordingly. Minor imprecision: the article says CVEs 'through September 30' (the table label), while Catanzaro's own technical note says the data is accurate through roughly September 1 because CVEs not yet assigned are not counted. Not material to any claim.
Overall Assessment: APPROVE. Accurate, carefully attributed coverage of a sensitive policy topic; all quotes verbatim, all figures traced and attributed, no unsourced claims in the title, summary or lead. The concerns are minor framing and single-source notes that do not warrant a corrections record.