@dalias Since you asked for feedback in the message:
I might consider swapping the position of "automated tools" and "AI" in some of the sentences, because I think a certain subset of people will hit "AI" and decide it doesn't apply to (say, hypothetically) the low quality static analyzer they're beating you with. Making it a slightly more general "no patches generated by automated anything unless you've convinced yourself they're fixing something real" might help stop that noise from good-intentioned actors.
Non-good-intentioned actors, of course, won't be stopped by a policy. So we can ignore those for now.