Skip to main content

Insights

Research & Evidence

Standards, research and industry evidence relevant to production assurance, rapidly built software and technical risk.

Lornets reviews primary research, recognised engineering standards, government guidance and transparent industry evidence. Source findings, Lornets interpretation and material limitations are kept distinct.

Records
24
Topics
9
Latest
2026

Evidence signals

Source-linked data points that surface a bounded finding. Each carries its source, response base, limitation and attribution. Results from different questions are never placed on one shared axis.

AI adoption is high. Trust in accuracy remains cautious.

AI adoption

84%

Using or planning to use AI tools in development

n = 33,662

Trust in output accuracy

Trust

33%

Distrust

46%

n = 33,244

Limitation
Survey respondents were recruited primarily through Stack Overflow channels. The two panels represent separate questions and different response bases. The results describe reported use and trust, not software quality or production readiness.
Attribution
Source: Stack Overflow Developer Survey 2025. Contains information made available under the Open Database License (ODbL) v1.0. Lornets visualisation of source data. AI-use and trust figures come from separate survey questions with different response bases.

Read the original research

Review burden differed by contributor-experience proxy in one large AI-assisted OSS dataset

Higher-experience group = 1x

Commits per PR

2.15x

Files changed per PR

1.47x

Review comments

4.52x

Resolution time

5.16x

Acceptance rate was 31% lower for the lower-experience group.

Limitation
The study uses historical GitHub contribution activity as a proxy for experience and examines AI-assisted pull requests in open-source repositories. The results should not be generalised directly to whole commercial applications or to developer skill generally.
Attribution
Source: Asdaque et al., "Novice Developers Produce Larger Review Overhead for Project Maintainers while Vibe Coding", MSR 2026, CC BY 4.0. Lornets visualisation adapted from reported results. Contributor experience is estimated using a GitHub activity proxy.

Read the original research

Evidence tensions

Where credible evidence points in different directions, the differences stay visible and what can be compared is stated plainly.

When does AI actually make software development faster?

  1. Substantial gains in large field experiments

    Three randomised field experiments covering 4,867 professional developers found a positive combined effect on completed development tasks.

    EVD-0011

  2. A measured slowdown in experienced maintainers

    A controlled study of experienced open-source developers working on real issues in repositories they knew well measured slower task completion when early-2025 AI tools were available.

    EVD-0013

  3. Local development gains meet system constraints

    DORA's research suggests AI acts as an amplifier of the wider engineering environment and that increased development velocity can interact with downstream delivery constraints.

    EVD-0009

The cited studies measure different outcomes and should not be presented as directly comparable effect sizes.

Explore the evidence tension

Standards and reference frameworks

Standards and government guidance sit in the same register as research, so a standard maps to framework domains and services in the same way. Lornets does not reproduce copyrighted standards material and is not affiliated with these organisations.

ISO/IEC 25010:2023

The current ISO SQuaRE product-quality model for specifying and evaluating ICT product quality.

Technical Standard

ISO / IEC, 2023

ISO/IEC 25040:2024

A current ISO SQuaRE standard covering the framework, concepts, requirements and process for evaluating ICT product, data and service quality.

Technical Standard

ISO / IEC, 2024

NIST Secure Software Development Framework v1.1

A risk-based set of secure software-development practices intended to be integrated into software-development lifecycles.

Current, revision underway

Government Guidance

National Institute of Standards and Technology, SP 800-218, SSDF v1.1, 2022

ISO/IEC 27001:2022

An international requirements standard for establishing, implementing, maintaining and continually improving an Information Security Management System.

Technical Standard

ISO / IEC, 2022 edition, with Amendment 1:2024 applicable, 2022

Cloud Controls Matrix and CAIQ v4.1

A structured cloud-security assurance framework and associated consensus assessment questionnaire.

Practitioner Reference

Cloud Security Alliance, 4.1, 2026

Browse the evidence

Records carry more than one topic where more than one applies. Nothing is forced into a single exclusive category.

Showing 24 of 24 records

2025

Industry Survey

Stack Overflow Developer Survey 2025: AI

84% of respondents to the relevant question said they were using or planning to use AI tools in development.

Stack Overflow

  • AI-Assisted Development
  • Rapidly Built Software

2026

Government Guidance

Supplier Assurance Questions

Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.

UK National Cyber Security Centre

  • Enterprise Assurance
  • Security & Supply Chain

2026

Practitioner Reference

Software Due Diligence

Technical diligence can examine product capability, architecture, technology stack, technical debt, R&D organisation, open-source use, hosting, cloud, cybersecurity and scalability.

Deloitte

  • Fundraise & Technical Diligence
  • Architecture & Platform Transition

2024

Government Guidance

NIST AI 600-1: Generative Artificial Intelligence Profile

The profile addresses risks including confabulation, data privacy, information integrity, information security and component integration.

National Institute of Standards and Technology

  • AI Assurance
  • Security & Supply Chain

2026

Practitioner Reference

Cloud Controls Matrix and CAIQ v4.1

CCM v4.1 contains 207 controls across 17 domains.

Cloud Security Alliance, 4.1

  • Enterprise Assurance
  • Security & Supply Chain

2022

Technical Standard

ISO/IEC 27001:2022

ISO/IEC 27001 addresses organisational information-security management.

ISO / IEC, 2022 edition, with Amendment 1:2024 applicable

  • Enterprise Assurance
  • Security & Supply Chain

2022

Technical Standard

ISO/IEC/IEEE 15026-2:2022 - Assurance Case

Assurance cases provide a structured way of connecting technical claims, arguments, evidence and assumptions.

ISO / IEC / IEEE

  • Software Quality & Maintainability
  • Reliability & Operations

2023

Technical Standard

ISO/IEC 25010:2023

The 2023 edition defines a product-quality model using nine quality characteristics.

ISO / IEC

  • Software Quality & Maintainability

2024

Technical Standard

ISO/IEC 25040:2024

Software quality evaluation is a process rather than merely a list of product characteristics.

ISO / IEC

  • Software Quality & Maintainability
  • Enterprise Assurance

2022

Government Guidance

NIST Secure Software Development Framework v1.1

SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.

Current, revision underway

National Institute of Standards and Technology, SP 800-218, SSDF v1.1

  • Security & Supply Chain
  • Software Quality & Maintainability

How we select evidence

Lornets prioritises primary technical standards, government and institutional guidance, peer-reviewed research and transparent industry evidence. Vendor and practitioner research may be included where useful and is identified by evidence type.

Source findings, Lornets interpretation and material limitations are kept distinct. Where credible evidence points in different directions, those differences are made visible rather than forced into a single conclusion.

Sources are periodically rechecked because standards, software platforms and AI engineering practices continue to change.

Evidence informs the methodology. It does not replace examination of a specific system.