Doing the opposite (disallowing AI), will place it on a path of getting riddled with security issues.
When attackers are using AI to both find vulnerabilities and build exploits faster than Debian can figure out how to patch the project without AI, you are saying Debian should not move quicker to fix these issues?