Guidelines  ·  2026-10-04

ENISA Draft Technical Advisory on AI-assisted software development — public consultation open (deadline 15 Oct 2026)

GuidelinesMedium impactEuropean Union
Around 17 September 2026 ENISA opened a public consultation (running to 15 October 2026) on a draft Technical Advisory on AI-assisted software development. The advisory argues 'functional code should not be confused with secure code,' identifies three risk areas (non-adversarial failures such as hallucinated dependencies; adversarial threats including prompt manipulation, malicious packages and misuse of agent privileges; and governance/assurance risks such as unclear accountability and excessive autonomy), and proposes a four-stage secure-by-design approach — Identify, Specify, Verify, Record — embedding security requirements directly into AI assistant/agent instructions and reusable 'skills.' It deliberately does not create a new compliance framework but applies existing secure-development expectations to AI-assisted workflows and links them to the EU Cyber Resilience Act.
This is the first EU-agency guidance specifically addressing the security of AI coding assistants and coding agents, a fast-growing attack surface. It gives practitioners a concrete, lightweight control model for AI-assisted development and signals the direction of future ENISA secure-by-design expectations tied to the CRA.
Submit comment feedback to ENISA before 15 October 2026, and map the Identify/Specify/Verify/Record approach onto existing SDLC and DevSecOps control frameworks.
ENISA LinkedIn — Call for Feedback (Draft Technical Advisory on AI-assisted software development)SCL Tech-law round-up (2 Oct 2026) — ENISA issues technical advisory on AI-assisted software developmentOpenSSF Newsletter September 2026 — ENISA consultation
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →