Build1 distinct publisher3 min readUpdated
An essay on dev.to argues ISO 27001, SOC 2 and NIST SP 800-53 were built around authenticated human decisions with a paper trail. AI sessions leave none, and you cannot reconstruct them later.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
An essay published on dev.to argues that ISO 27001, SOC 2 and NIST SP 800-53 rest on an assumption chain that no longer holds: a human made the decision, that human was authenticated and authorised to make it, the decision was documented in a ticket or comment or change record, and if something broke you could trace back to who decided what [1][2]. The reason this is a deadline and not a debate is that certification certifies a snapshot as of a date [12], and the artefact an auditor will ask for may already have been destroyed by the time they ask.
The author's version of the honest answer many teams would now give an auditor working through change management: "We described the problem to Claude, it suggested this implementation, we thought it looked right, and we merged it" [3]. According to the piece, that answer is not covered anywhere in ISO 27001, barely appears in SOC 2, and NIST is only now beginning to grapple with it, with the gap widening weekly against how teams actually work in 2026 [4][15].
At control level the problem is specific rather than philosophical. SOC 2 CC6.6 requires that changes to infrastructure and software are authorised, tested and documented before deployment, and most interpretations assume a human reviewer in the loop who exercised judgment [5][6]. The piece notes that "a developer approved the PR" remains technically true even when the review consisted of reading an AI-generated summary of the AI's own change, which leaves the question of what judgment was exercised and by whom [7]. The auditor's phrasing it anticipates is mundane: walk me through how this change was reviewed before it was approved [8].
The logging side is worse because it is not a matter of interpretation. NIST SP 800-53 AU-2 through AU-12 cover audit and accountability, including which events are logged, how records are retained, and how they can be reconstructed for investigation [9] - eleven numbered controls [1]. By default, the piece says, none of your AI coding sessions are covered by any of it, and they leave no audit record whatsoever despite producing real changes to production systems [10]. Commits are logged, database queries traced, API calls metered; the CI/CD pipeline has more observability than the sessions increasingly driving what goes through it [11]. AI coding tools are not authenticated, do not sign commits, and have no name in the issue tracker, and the conversation behind an architectural decision may exist for exactly as long as the browser tab stays open [13].
The data-handling exposure runs on the same missing log. GDPR Article 30 requires records of processing activities and ISO 27001 Annex A.15 covers supplier relationships [14], while in practice developers paste production schemas, error logs carrying user context and architecture details into prompts; some organisations forbid it, most do not, and enforcement is near zero because nothing records what was shared or when [c15b].
The operational consequence is retention, not policy. Session transcripts, prompt logs and a reviewer attestation that names what a human actually checked are cheap to start capturing today and impossible to backfill for a period that has already closed [13][10]. The author's view is that auditors are increasingly unable to assess whether existing controls account for the daily AI sessions in an engineering org [16], which means the finding, when it lands, will be about missing evidence rather than a bad decision.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
NIST SP 800-53 AU-2 through AU-12 cover audit and accountability: what events are logged, how records are retained, and how they can be reconstructed for investigation.
ISO 27001, SOC 2 Type II and NIST SP 800-53 were designed around the assumptions that a human made a decision, that human was authenticated and authorized to make it, the decision was documented in a ticket, comment, change record or signature, and that if something went wrong you could trace back to who decided what.
SOC 2 CC6.6 requires that changes to infrastructure and software are authorized, tested, and documented before deployment.
When an organization gets ISO 27001 certified or completes a SOC 2 Type II audit, auditors are certifying a snapshot: as of this date, these controls were in place.
GDPR Article 30 requires records of processing activities, and ISO 27001 Annex A.15 covers supplier relationships and information security within them.
The range AU-2 through AU-12 spans 11 numbered NIST SP 800-53 controls.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One self-published essay; real control citations, no external corroboration
The cluster rests on a single dev.to opinion piece. Its descriptive claims about named provisions — SOC 2 CC6.6, NIST SP 800-53 AU-2..AU-12, ISO 27001 Annex A.15, GDPR Article 30, and the point-in-time nature of certification — are specific and internally consistent, which supports a floor of evidentiary value. Everything load-bearing beyond that (prevalence of AI-merged changes, total absence of session records, auditors' inability to assess, near-zero policy enforcement) is asserted without survey, telemetry, audit finding, vendor documentation or third-party attribution, and there is no second publisher to corroborate or contest any of it.
No adoption facts supplied
The supplied source reports no releases, deployments, benchmarks, pricing or licence changes, usage disclosures or named-organization practices. Its only proximity to adoption is unquantified characterizations of what 'many teams' and 'most organizations' do, which cannot be converted into an adoption measurement without inventing facts.
Absolute and trend language outruns the supplied support
The argument is stated with more certainty than the material carries: sessions leave 'no audit record whatsoever', the framework-practice gap is 'widening every week', auditors are 'increasingly unable' to assess coverage, and enforcement is 'near-zero'. None of these is measured, attributed or bounded, and no counter-evidence (enterprise AI-tool audit logs, admin retention settings, auditor guidance) is engaged. The gap is moderate rather than severe because the underlying control citations are real and the structural point — that control language and audit procedures presume an authenticated human actor — is coherently made from those citations.
No incentive disclosure available
The source provides no author affiliation, employer, vendor relationship, product, funding or commercial call to action beyond generic governance advice, and there is no second publisher whose positioning could be compared. Assigning an incentive score would require inferring a commercial motive the supplied material does not evidence.
Low: single-voice essay, verifiable only on framework citations
Confidence is limited by the one-source, one-publisher structure and by the fact that framing and evidence originate from the same author. It is not lower because the framework-provision descriptions are specific and mutually consistent, the reasoning chain from control assumptions to missing evidence is transparent, and the piece's own remedies are testable by any team that checks its audit scope. Adoption and incentive dimensions are unmeasurable from this material, which further caps confidence in the story as a whole.
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
invest
Kraken's parent now runs a security model that Washington can switch off1 distinct publisher
science
Text watermarks land on 2 December. The detection they imply does not.1 distinct publisher
build
1,500 submissions in 14 days: what a 12th-place GPU kernel says about agent loops1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 19, 2026