I don't think ignoring AI and remaining relevant is an option that is available to Debian, at least insofar as Information Security. AI code analysis in search of vulnerabilities is a significant force multiplier, to the point that we are flooded with CVEs for almost every major commercial product. AI's ability to identify vulnerabilities in existing code is already working very well, ability to preemptively fix these issues during AI-generated code is still being worked on. As such, very soon AI generated code will be a lot more secure than average human-generated code.