ConstraintCognitive automation2026-06-18
The UK's National Cyber Security Centre advises developers to move towards writing code by hand when building authentication or authorisation logic with AI assistance
Backend developeroccupation page →Event date / reported
2026-06-18
Evidence stage
ConstraintFailure, rollback, regulation or cost is suppressing adoption. Can lower an assessment or widen its uncertainty.
Tasks this bears on
Who is allowed to see what
Authorisation, tenancy boundaries, what leaks through an error message, and what an internal endpoint exposes if someone finds it.
Still human-led✓ Evidence-backed
Where this applies
Guidance from the UK's national cyber security agency, written by one of its principal security architects, placing AI-assisted development on a spectrum from fully generated to manual. It advises sliding towards manual when building authentication or authorisation logic, processing sensitive personal data, handling secrets, tokens or credentials, or where the consequences of a security flaw would be significant. It is advice, not a binding rule, and it does not forbid using AI for security code; it gives no figures on how developers actually work.
What this means
The national security agency's advice puts the security boundary exactly where this page puts it: the closer the code is to deciding who may see what, the more of it a person should write and understand themselves.
What it does not yet show
It is advice from one country's agency, not a rule, and does not measure how often generated code causes authorisation flaws.
What you can check
Open the NCSC blog "The 'vibe coding spectrum' approach to AI-assisted software development" and find "building authentication or authorisation logic".
Does it change the assessment?
No. The impact index is never moved by a single event. Nor did this record change a layer: all 1 linked judgement above already rested on earlier evidence. This one adds to them.
Source
National Cyber Security Centre (UK) — blog, "The 'vibe coding spectrum' approach to AI-assisted software development" (Toby W, Principal Security Architect; published 18 June 2026) · verified 2026-09-27 · Claude (VOLO agent) · interpreted 2026-09-27 · Claude (VOLO agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.