Trust in AI-Generated Software: Why verification, not generation, is the new bottleneck – a European perspective

Large language models now write a substantial share of new source code, yet the mechanisms by which organisations establish confidence in that code have hardly changed. Independent testing indicates that AI-generated code introduces security weaknesses in close to half of evaluated tasks, while European regulation – notably the Cyber Resilience Act and the AI Act – places increasing responsibility on those who place software on the market. This paper argues that the decisive constraint on the productive use of AI in software engineering is no longer the generation of code but its verification. It describes the structural sources of the resulting trust gap, outlines the European regulatory context, and proposes six design principles for a "trust layer" that sits between AI coding agents and production systems. Particular attention is given to small and medium-sized enterprises and to regulated organisations that cannot transfer source code to external cloud services.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-06
DOI
https://doi.org/10.5281/zenodo.23188464
Primary Topic
Safety Systems Engineering in Autonomy
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Trust in AI-Generated Software: Why verification, not generation, is the new bottleneck – a European perspective

Steinemann Hermann
Zenodo (CERN European Organization for Nuclear Research)
Safety Systems Engineering in Autonomy
article

Trust in AI-Generated Software: Why verification, not generation, is the new bottleneck – a European perspective

Steinemann Hermann
article en

Abstract

Large language models now write a substantial share of new source code, yet the mechanisms by which organisations establish confidence in that code have hardly changed. Independent testing indicates that AI-generated code introduces security weaknesses in close to half of evaluated tasks, while European regulation – notably the Cyber Resilience Act and the AI Act – places increasing responsibility on those who place software on the market. This paper argues that the decisive constraint on the productive use of AI in software engineering is no longer the generation of code but its verification. It describes the structural sources of the resulting trust gap, outlines the European regulatory context, and proposes six design principles for a "trust layer" that sits between AI coding agents and production systems. Particular attention is given to small and medium-sized enterprises and to regulated organisations that cannot transfer source code to external cloud services.

Zenodo (CERN European Organization for Nuclear Research)
Openalex Percentile: Top 11%
Safety Systems Engineering in Autonomy
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.