Notes from the factory
Shipping production AI apps, agent-assisted engineering, and fixed-price delivery for the German mid-market.
- ai-governance6 min
GitHub Copilot Enterprise Audit Logs: What They Capture and What They Miss for AI Code Governance
GitHub Copilot Enterprise ships audit logs for admin actions and policy changes, but engineering leaders evaluating it for AI code governance often assume those logs also cover what Copilot suggested and what got merged. They don't — and that gap is where governance programs quietly fail their next audit.
- ai-governance4 min
EU AI Act August 2026 Deadline: What Applies to AI Coding Agents
The EU AI Act's high-risk deadline moved to December 2027, but Article 50 transparency, GPAI penalty enforcement, and market surveillance authority still activate August 2, 2026 — and all three can reach a pull request.
- ai-governance4 min
AI Coding Agent Runaway Detection: Five Signals That a Model Is Producing Off-Pattern Code
AI coding agents go off-pattern before anyone notices — and 42% of committed code is now AI-generated. Here are five behavioral signals that flag a model producing anomalous output before it reaches production.
- ai-governance5 min
ISO 27001 and AI Coding Agents: Which Controls Need Updating Before Your Next Audit
AI coding agents create evidence gaps in ISO 27001:2022 controls for supplier relationships, secure development, and cloud services. Here is which Annex A controls need AI-specific scope updates before your auditor asks.
- ai-governance4 min
AI Coding Agent Procurement: A Security Due Diligence Checklist for Engineering Leaders
Seven security due diligence questions every engineering leader must ask before authorizing an AI coding agent for enterprise use — covering data handling, audit logs, supply chain risk, and access control.
- ai-governance4 min
GDPR and AI-Generated Code: Three Data Privacy Risks in Every Pull Request
AI coding agents create GDPR exposure points most teams have not mapped — purpose expansion, personal data in context windows, and undocumented third-party data transfers. Here is what engineering teams need to govern before the next pull request merges.
- ai-governance4 min
AI-Generated Code Attribution: How to Track What Your Agents Wrote in Pull Requests
Most engineering teams cannot answer which pull requests were written by an AI coding agent. This guide shows how to build attribution tracking into your PR workflow before compliance deadlines force the issue.
- ai-governance4 min
How to Measure AI Code Governance Maturity in Your Engineering Org
Only 13% of engineering organizations have governance structures for AI coding agents. This four-level maturity model gives you a scored baseline and a concrete path to enforcement and optimization.
- ai-governance4 min
How to Build a Business Case for AI Code Governance: Numbers That Land With Leadership
Engineering leaders have the risk data — 45% AI code failure rates, a $670K shadow AI breach premium. Here is how to structure the business case so finance and security leadership act on it.
- ai-governance4 min
NIST AI RMF for AI Coding Agents: A Practical Mapping for Engineering Teams
The NIST AI Risk Management Framework's four functions map directly onto AI coding agent governance gaps — here is how engineering teams can apply GOVERN, MAP, MEASURE, and MANAGE at the pull request level.
- ai-governance5 min
SOC 2 and AI-Generated Code: What Your Next Audit Will Ask About
SOC 2 auditors are mapping Trust Services Criteria to AI coding agent activity before formal AICPA guidance exists. Here is what engineering teams need to document now.
- ai-governance4 min
How to Write an Acceptable Use Policy for AI Coding Agents
Most enterprise AI policies were designed for chatbots, not coding agents that commit code, call APIs, and open pull requests autonomously. Here is what an acceptable use policy for AI coding agents must cover.
- ai-governance4 min
What to Look for in an AI Code Governance Platform: Five Capabilities That Actually Matter
45% of AI-generated code contains known security vulnerabilities. Engineering teams evaluating AI code governance platforms need to know the five capabilities that separate real enforcement from security theater.
- ai-governance4 min
How Automated PR Risk Scoring Keeps AI-Generated Code From Slipping Past Review
31% of AI-assisted pull requests now merge without any review. This guide explains how automated PR risk scoring works in CI pipelines to triage AI-generated code at scale.
- ai-governance8 min
Who Owns EU AI Act Compliance? Six Misconceptions Engineering Organizations Need to Correct
The EU AI Act creates overlapping obligations for providers and deployers — but accountability often falls through the cracks. Six misconceptions GRC leads and compliance engineers must correct.
- ai-governance4 min
How to Set a Pull Request Size Policy for AI-Generated Code
AI-generated pull requests contain up to 2.74x more security vulnerabilities than human-written ones and arrive far larger than standard review processes can absorb. Here is how to define and enforce a PR size policy built for the age of AI coding agents.
- ai-governance4 min
AI-Generated Code License Compliance: What Engineering Teams Must Check Before Merging
AI coding agents can silently introduce copyleft license obligations into your codebase. Here is how engineering teams can detect, track, and govern license risk in AI-generated pull requests.
- ai-governance4 min
Five Metrics Every Engineering Team Should Track for AI-Generated Code Risk
AI-generated code introduces 1.7x more issues than human-written code. Here are the five metrics engineering teams should track to govern AI-assisted codebases before risk accumulates.
- ai-governance4 min
What Pull Request Risk Scoring Catches That Code Review Misses
Manual code review misses the systematic vulnerabilities AI coding agents introduce at scale. This is what pull request risk scoring catches instead.
- ai-governance8 min
EU AI Act Conformity Assessment: A Step-by-Step Approach for Engineering Teams
What the EU AI Act's conformity assessment process generally requires for high-risk AI systems, the five steps engineering teams should work through, and how to navigate the choice between internal control and third-party notified body review.
- ai-governance4 min
Your PR Review Process Was Designed for Human Code. AI Just Changed the Math.
AI-generated pull requests carry nearly twice the defect rate of human-authored ones—and standard review workflows weren't built for that. Here's what the data shows and what engineering teams need to change.
- ai-governance9 min
Human Oversight of AI Coding Agents: Addressing EU AI Act Article 14
EU AI Act Article 14 requires specific human oversight capabilities for high-risk AI systems. Here is what the regulation generally requires and how development teams can begin building compliant oversight controls for AI coding agents before the August 2026 application date.
- ai-governance8 min
AI Code Review Policy: The Six Components Every Engineering Team Needs in 2026
Only 18% of enterprises have formal guidelines for AI-generated code, yet AI now accounts for 42% of all committed code. Here is what a working AI code review policy actually contains and how to enforce it at the pull request level.
- ai-governance8 min
How to Govern Autonomous Coding Agents: A Practical Framework for Engineering Teams
A four-layer governance framework for autonomous coding agents — covering pre-task policy, PR risk scoring, human escalation rules, and audit trail — with 2026 data on why ungoverned agents are a production risk.
- ai-governance8 min
FMEA for AI Pull Requests: How to Score Risk Before It Ships
Learn how to apply Failure Mode and Effects Analysis (FMEA) methodology to AI-generated pull requests — scoring severity, occurrence, and detection to prioritize the risks that actually ship to production.
- ai-governance4 min
How to Set Up a GitHub Copilot Enterprise Governance Policy: A 5-Step Guide
A practical five-step guide to building a GitHub Copilot enterprise governance policy — covering usage audits, acceptable use rules, enterprise controls, PR-layer enforcement, and ongoing monitoring.
- ai-governance8 min
How to Build an AI Code Audit Trail That Addresses EU AI Act Article 12
Article 12 of the EU AI Act generally requires high-risk AI systems to support automatic event logging over the lifetime of the system. This guide explains what that means for AI-assisted development workflows and what a minimal viable audit trail may look like.
- ai-governance8 min
EU AI Act Compliance Requirements: A Practical Checklist for Dev Teams
A structured compliance checklist covering EU AI Act Articles 9-15 — risk management, data governance, logging, transparency, and human oversight requirements for high-risk AI systems in software development.
- ai-governance8 min
Audit Trail for AI-Generated Code: What Compliance Actually Requires in 2026
With EU AI Act Article 12 enforcement arriving August 2026, engineering teams must build structured audit trails for every AI-generated code change — capturing model version, prompt context, reviewer identity, and test outcomes. Here is what the regulation actually requires and where most teams fall short.
- ai-governance8 min
FMEA for AI Pull Requests: Applying Failure Mode Analysis to AI-Generated Code Risk
FMEA for AI pull requests applies the same failure mode and effects analysis engineering teams use for physical systems to identify and prioritize risk in AI-generated code before it merges.
- ai-governance8 min
How to Govern Autonomous Coding Agents: A Practical Framework for Engineering Teams
Autonomous coding agents now generate an estimated 41% of global code, yet most engineering teams have no formal governance framework for them. Six practical steps — from agent identity assignment to continuous monitoring — that engineering teams can implement without a security-team mandate.
- ai-governance9 min
AI Code Review Policy: Why Written Rules Aren't Enough (And What Actually Works)
45% of AI-generated code contains security vulnerabilities. Most engineering teams have a policy document. Almost none have enforcement infrastructure. Here is what the difference looks like — and how to close the gap.