---
title: "ENISA warns on AI-assisted software development: working code does not mean secure code"
description: ENISA warns that AI-assisted software development can introduce security risks; secure coding practices are essential for safe implementation and compliance.
image: https://blog.isecauditors.com/hubfs/el-ria-ya-se-supervisa-cumplir-significa-poder-demostrarlo.png
---

English

- [Spanish](https://blog.isecauditors.com/enisa-alerta-sobre-el-desarrollo-asistido-por-ia-que-el-c%C3%B3digo-funcione-no-significa-que-sea-seguro)
- [English](https://blog.isecauditors.com/en/enisa-warns-on-ai-assisted-software-development-working-code-does-not-mean-secure-code)

[![290x123px\_isecauditors](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/290x123px_isecauditors.png?width=290&height=91&name=290x123px_isecauditors.png) ![290x123px\_isecauditors](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/290x123px_isecauditors.png?width=290&height=91&name=290x123px_isecauditors.png)](https://blog.isecauditors.com/?hsLang=en)

- [← www.isecauditors.com](https://www.isecauditors.com/)
- [academy.isecauditors.com](https://academy.isecauditors.com/)

- [← www.isecauditors.com](https://www.isecauditors.com/)
- [academy.isecauditors.com](https://academy.isecauditors.com/)

[ISO 42001](https://blog.isecauditors.com/en/tag/iso-42001) [AIR](https://blog.isecauditors.com/en/tag/air) [Implementation of an SGIA](https://blog.isecauditors.com/en/tag/implementation-of-an-sgia)

# ENISA warns on AI-assisted software development: working code does not mean secure code

[Alberto Villar Arévalo](https://blog.isecauditors.com/en/author/alberto-villar)  Oct 2, 2026, 1:44:12 PM

Madrid, 1 October 2026. ENISA has published version 0.4 of its Technical Advisory on AI-assisted software development with a direct message for any organisation using coding assistants or development agents: software that compiles, works or completes the requested task is not necessarily secure. The document highlights risks such as vulnerabilities introduced by lack of context, hallucinated or outdated recommendations, unwanted changes, insufficient review, secret leakage and abuse of permissions.

*As the autonomy of these tools increases —from point suggestions to agents that can configure, test, manage dependencies or execute complex tasks— so does the need for control, traceability and human approval. ENISA stresses that AI-assisted development should be integrated into existing secure development processes rather than treated as an exception or as “trusted automation” by default.*

Its practical approach can be summarised in four steps: identify the process and applicable requirements; communicate them consistently to the assistant or agent; review and verify the results through human approval, testing and security controls such as SAST, DAST, dependency, integrity and secret analysis; and retain evidence of what was done, approved and deployed. ENISA also makes clear that instructions or reusable skills help, but do not guarantee secure results and do not replace organisational accountability.

This directly connects with the EU AI Act and ISO/IEC 42001. Using coding assistants does not automatically trigger the same AI Act obligations in every scenario: applicability depends on the system, its purpose and the organisation’s role. Where the Regulation applies, decisions on oversight, risk management, third parties and evidence must be demonstrable. ISO/IEC 42001, while voluntary, provides a particularly useful management framework to structure governance, responsibilities, controls and continual improvement for corporate AI use.

Internet Security Auditors can support organisations through a combined EU AI Act + ISO/IEC 42001 GAP Assessment, a prioritised Action Plan, implementation support, internal audit and technical audit of the AI ecosystem. Where risk justifies it, we can also complement the work with secure development lifecycle reviews, technical testing and ethical hacking of applications, APIs, CI/CD pipelines and agent integrations.

![enisa-warns-working-ai-generated-code-is-not-necessarily-secure-code](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/enisa-warns-working-ai-generated-code-is-not-necessarily-secure-code.png?width=1316&height=740&name=enisa-warns-working-ai-generated-code-is-not-necessarily-secure-code.png)

[\[1\] ENISA — Technical Advisory on AI-assisted software development, version 0.4 (September 2026).](https://www.enisa.europa.eu/sites/default/files/2026-09/ENISA%20Technical%20Advisory-AI-assisted-software-development-draft.pdf)  
[\[2\] Regulation (EU) 2024/1689 — European Union Artificial Intelligence Act.](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng)  
[\[3\] ISO — ISO/IEC 42001:2023, Artificial intelligence management systems.](https://www.iso.org/standard/42001)  
[\[4\] Internet Security Auditors — AI Usage Compliance Assessment and Support.](https://www.isecauditors.com/index.php/evaluacion-y-soporte-al-cumplimiento-uso-inteligencia-artificial)  
[\[5\] Internet Security Auditors — ISO/IEC 42001 AIMS Implementation.](https://www.isecauditors.com/implementacion-sgia-iso-42001)  
[\[6\] Internet Security Auditors — Comprehensive Security Audit for AI Ecosystems.](https://www.isecauditors.com/auditoria-integral-de-seguridad-para-ecosistemas-de-IA)  
[\[7\] Sources consulted on 1 October 2026.](https://www.enisa.europa.eu/)

- [Tweet](https://twitter.com/share)

---

![author-image](https://blog.isecauditors.com/hubfs/Logo_isecauditors_contraccion_HP.png)

[Alberto Villar Arévalo](https://blog.isecauditors.com/en/author/alberto-villar)

PCI SSA, PCI QSA, CISSP, CSSLP, ISO 27001 L.A., CSFPC, SFPC   
 Security Consultant   
 Consulting Department

---

[Legal Notice](https://www.isecauditors.com/aviso-legal)

[Policy Privacy](https://www.isecauditors.com/politica-privacidad)

[Cookie Policy](https://www.isecauditors.com/politica-cookies)

<https://www.facebook.com/ISecAuditors> <https://twitter.com/ISecAuditors> <https://www.instagram.com/ISecAuditors/> <https://www.linkedin.com/company/internet-security-auditors/> <https://www.youtube.com/ISecAuditors>

---

Copyright © 2026 - All rights reserved

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Alberto Villar Arévalo",
    "url" : "https://blog.isecauditors.com/en/author/alberto-villar"
  },
  "dateModified" : "2026-10-02T11:44:12.722Z",
  "datePublished" : "2026-10-02T11:44:12.000Z",
  "headline" : "ENISA warns on AI-assisted software development: working code does not mean secure code",
  "image" : [ "https://blog.isecauditors.com/hubfs/el-ria-ya-se-supervisa-cumplir-significa-poder-demostrarlo.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.isecauditors.com/en/enisa-warns-on-ai-assisted-software-development-working-code-does-not-mean-secure-code",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.isecauditors.com/hubfs/isec_logo.png"
    },
    "name" : "Internet Security Auditors, S.L."
  }
}
```