What happened
Around 17 September 2026 ENISA opened a public consultation (running to 15 October 2026) on a draft Technical Advisory on AI-assisted software development. The advisory argues 'functional code should not be confused with secure code,' identifies three risk areas (non-adversarial failures such as hallucinated dependencies; adversarial threats including prompt manipulation, malicious packages and misuse of agent privileges; and governance/assurance risks such as unclear accountability and excessive autonomy), and proposes a four-stage secure-by-design approach — Identify, Specify, Verify, Record — embedding security requirements directly into AI assistant/agent instructions and reusable 'skills.' It deliberately does not create a new compliance framework but applies existing secure-development expectations to AI-assisted workflows and links them to the EU Cyber Resilience Act.
Why it matters
This is the first EU-agency guidance specifically addressing the security of AI coding assistants and coding agents, a fast-growing attack surface. It gives practitioners a concrete, lightweight control model for AI-assisted development and signals the direction of future ENISA secure-by-design expectations tied to the CRA.
Action needed
Submit comment feedback to ENISA before 15 October 2026, and map the Identify/Specify/Verify/Record approach onto existing SDLC and DevSecOps control frameworks.