This text is in response to a recent blog post by Michael Catanzaro, the maintainer of GNOME's Epiphany browser (of which I am a happy user) and someone who has touched many other core GNOME projects.
The Era of Software Quality, of the Era of Ostriches?
I urge you to read it in order to understand his points, because they are utterly unhinged.
First, he claims that
There is zero hope of maintaining quality software in 2026 without AI vulnerability scanning.
I strongly disagree. To understand why, let's see what Catanzaro has to say about the reliability of these tools.
Have you heard that most AI bug reports are “slop?” Not so in 2026. That was true for most of 2025, but the quality of AI-generated vulnerability reports has drastically improved.
AI-generated vulnerability reports have nevertheless introduced many undesirable impacts on GNOME maintainers. They are usually annoyingly verbose and unnecessarily detailed. They often exaggerate the severity of the problem, or make misleading or irrelevant claims. They are occasionally incorrect. Sometimes they include outright fabricated data, such as fake stack traces (which is not the norm, but sadly also not uncommon).
Even when the generated issue report is good and avoids all of the above problems (which is rare), good vulnerability reports in sufficiently high quantity can still overwhelm volunteer maintainers.
At once, Catanzaro claims that probabilistically-generated bug reports must be permitted in 2026, and that they are unreliable and a waste of everyone's time. He notes that people who would've claimed generative tooling was a gamechanger in 2025 would have effectively been fools, but that those same claims in 2026 are somehow accurate. What has changed of the underlying technology? Nothing. At their core, language models are the same today that they were yesterday except now they're also trained on the slop that is taking over the entire Internet. The only "advancement" in related tooling today is that people have figured out how to use language models to generate and execute computer commands sight unseen, giving rise to a perceived "agency" in what continues to be glorified autocomplete.
What's really maddening—what makes me feel like I've taken the proverbial crazy pills, or like I've entered a so-called Bizarro World where everything is nonsensical—is the sheer self-contradiction of Catanzaro's points. According to him, generative tools are at once highly unreliable and utterly necessary.
This is not a serious position. A serious person would not take this post seriously other than as a sign that one should absolutely not take Catanzaro seriously. In my mind, the only way to square that post's two diametrically opposed viewpoints is to assume that its author believes companies like OpenAI and Anthropic will soon fix all the issues in language models, such as the so-called "hallucinations" that are interent to a model which randomly generates statistically-plausible text. In other words, one needs to be delusional to expect to be taken seriously for saying this.
Speaking of being as tethered to reality as a chatbot—which is to say, only by coincidence—Catanzaro predictably has nothing to say about the various effects that chatbots and their use have on the world around them. Nothing about how web services are overstressed from the constant scraping for more text to shove into models, nothing about how this wretched bubble has inflated computer hardware prices to such a ridiculous degree that ordinary consumers struggle to afford the computer hardware on which one would run GNOME software, nothing about the dire financial situation facing the US economy as a direct result of this bubble, nothing of how the worst AI boosters as siphoning funding from projects like GNOME in order to assert control over the free desktop ecosystem, nothing about all the coal-fired power plants being brought online to power "AI" data centres, nothing about how impoverished communities are bearing the brunt of increasing pollution and energy prices, nothing of how so-called "AI" tech disproportionally affects marginalized people, nothing about studies that raise serious questions regarding the mental effects of continuous chatbot usage, and nothing of these omissions surprises me because it would mean that he would need to interrogate the harms of the tech which he so strongly advocates.
Speaking of advocacy, Catanzaro in that post advocates that
GNOME maintainers should rewrite their AI contribution policies to permit AI-generated vulnerability reports, as I previously requested four months ago.
And, the coup de grâce:
Projects that continue to prohibit AI-generated vulnerability reports are no longer suitable dependencies for GNOME, and should be developed someplace other than GNOME GitLab.
Let me see if I understand this correctly.
Against their will, GNOME project maintainers must be made to accept generated bug reports which per Catanzaro himself are likely to be filled with inaccuracies and fabrications and that he supports such an extreme measure on the grounds that said reports may possibly lead to sometimes fixing a real security issue. All of this is regardless of the social consequences of this technoligy as well as regardless of anyone's preference not to be exposed to the bullshit extrusion machine.
Toward the idea that others should not be made to rewrite AI-generated reports before submitting them, he says
Rewriting issue reports also does not scale. Let’s say you use AI to find 100 security bugs in a GNOME project, a number consistent with the results of actual scans (read on). Would you really spend months rewriting those bug reports before submitting them to upstream? Validating the AI’s claims, upstreaming the issue reports, and submitting merge requests is already a lot of work. Not many people would be willing to additionally rewrite all the issue reports. That’s more work than everything else combined, and is unrealistic.
Michael Catanzaro says that because these alleged bug reports could be real, maintainers should be willing to accept something submitted by someone who could not even be bothered to write it themselves. Reporters should not be obligated to write accurate reports describing their own observations because it takes too much time. Actually using one's own words to describe a problem they've observed "does not scale" which means we must all accept probabilistic generation which definitionally cannot have an understanding of a problem. This is apparently a serious call for a GNOME-wide policy change. What a joke.
The fact is that it is entirely reasonable to expect a reporter to have actually observed a bug, to be able to describe the bug they've observed, and to include information from their experiments.
If these chatbots have somehow (against the limits of what is mathematically possible) discovered how to reliably find security bugs, then it should be relatively easy to uncover and formalize the underlying principles in order to create a new generation of deterministic security tooling without the language model nonsense. Once that hypothetical tooling actually exists, then we can have another conversation about whether the benefits are worth the cost. As it stands, GNOME project maintainers have made their choice on the matter and that choice must to be respected—even by techbros who can't move on from getting one-shot by a chatbot.