‘The continued flood of AI reports has basically made the security list almost entirely unmanageable’: Linus Torvalds laments how people are wasting the Linux team’s time with LLMs
Linus Torvalds has criticized developers for submitting incomplete bug reports to the Linux kernel security mailing list that were generated using AI tools. In a post on the Linux mailing list, the Linux creator expressed frustration—not with the use of AI tools themselves, but with submissions that lack substantive analysis or follow-up work. These AI-generated reports flood the security list with low-quality entries that essentially state “here’s a bug” without providing the necessary context, testing, or investigation that kernel developers need to act on them.
According to Torvalds, the proliferation of these incomplete reports has made the security mailing list “almost entirely unmanageable.” Rather than benefiting the Linux project, these AI-assisted submissions waste the kernel team’s valuable time by requiring them to sort through numerous reports lacking the foundational work needed for proper bug triage and resolution. The complaint highlights a broader tension in software development: while AI tools can effectively identify potential issues, their value depends entirely on whether developers take responsibility for properly investigating and documenting findings before submitting them.
Torvalds’ criticism underscores the importance of responsible tool usage in collaborative development. He is not objecting to AI itself, but rather to developers who use these tools without performing the necessary follow-up work to make discoveries actionable and worthy of developer attention.