Trust in AI-Generated Software: Why verification, not generation, is the new bottleneck – a European perspective
Large language models now write a substantial share of new source code, yet the mechanisms by which organisations establish confidence in that code have hardly changed. Independent testing indicates that AI-generated code introduces security weaknesses in close to half of evaluated tasks, while European regulation – notably the Cyber Resilience Act and the AI Act – places increasing responsibility on those who place software on the market. This paper argues that the decisive constraint on the productive use of AI in software engineering is no longer the generation of code but its verification. It describes the structural sources of the resulting trust gap, outlines the European regulatory context, and proposes six design principles for a "trust layer" that sits between AI coding agents and production systems. Particular attention is given to small and medium-sized enterprises and to regulated organisations that cannot transfer source code to external cloud services.
Authors
- Steinemann Hermann
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-06
- DOI
- https://doi.org/10.5281/zenodo.23188464
- Primary Topic
- Safety Systems Engineering in Autonomy
- Type
- article
- Field-Weighted Citation Impact
- 0.00