Rapid creation. Thinner production evidence.
Vibe Coding in Software Development: A Multivocal Literature Review
Preprint / Working Paper / arXiv
Insights
Standards, research and industry evidence relevant to production assurance, rapidly built software and technical risk.
Lornets reviews primary research, recognised engineering standards, government guidance and transparent industry evidence. Source findings, Lornets interpretation and material limitations are kept distinct.
Selected for what they change in an assurance decision
Rapid creation. Thinner production evidence.
Vibe Coding in Software Development: A Multivocal Literature Review
Preprint / Working Paper / arXiv
AI amplifies the engineering system around it.
State of AI-assisted Software Development 2025
Industry Research / DORA / Google Cloud
Production failures extend beyond source code.
How to Fight Production Incidents? An Empirical Study on a Large-Scale Cloud Service
Peer-Reviewed Research / Microsoft Research / ACM SoCC 2022
Migration changes the risk surface rather than simply removing it.
Incidents During Microservice Decomposition: A Case Study
Peer-Reviewed Research / Carbon Health / EASE 2025
Source-linked data points that surface a bounded finding. Each carries its source, response base, limitation and attribution. Results from different questions are never placed on one shared axis.
AI adoption
84%
Using or planning to use AI tools in development
n = 33,662
Trust in output accuracy
Trust
Distrust
n = 33,244
Higher-experience group = 1x
Commits per PR
Files changed per PR
Review comments
Resolution time
Acceptance rate was 31% lower for the lower-experience group.
Where credible evidence points in different directions, the differences stay visible and what can be compared is stated plainly.
Substantial gains in large field experiments
Three randomised field experiments covering 4,867 professional developers found a positive combined effect on completed development tasks.
A measured slowdown in experienced maintainers
A controlled study of experienced open-source developers working on real issues in repositories they knew well measured slower task completion when early-2025 AI tools were available.
Local development gains meet system constraints
DORA's research suggests AI acts as an amplifier of the wider engineering environment and that increased development velocity can interact with downstream delivery constraints.
The cited studies measure different outcomes and should not be presented as directly comparable effect sizes.
Standards and government guidance sit in the same register as research, so a standard maps to framework domains and services in the same way. Lornets does not reproduce copyrighted standards material and is not affiliated with these organisations.
The current ISO SQuaRE product-quality model for specifying and evaluating ICT product quality.
Technical Standard
ISO / IEC, 2023
A current ISO SQuaRE standard covering the framework, concepts, requirements and process for evaluating ICT product, data and service quality.
Technical Standard
ISO / IEC, 2024
A standard specifying requirements for the structure and terminology of assurance cases.
Technical Standard
ISO / IEC / IEEE, 2022
UK government software-assurance guidance decomposing software-security principles into claims that should be supported by appropriate evidence.
Government Guidance
UK National Cyber Security Centre, 2026
A structured application-security verification standard containing concrete requirements for assessing technical security controls.
Practitioner Reference
OWASP Foundation, 5.0.0, 2025
A risk-based set of secure software-development practices intended to be integrated into software-development lifecycles.
Current, revision underway
Government Guidance
National Institute of Standards and Technology, SP 800-218, SSDF v1.1, 2022
A voluntary risk-management framework for organisations designing, developing, deploying or using AI systems.
Current, revision underway
Government Guidance
National Institute of Standards and Technology, 2023
A Generative AI profile extending the NIST AI Risk Management Framework with risks and actions particularly relevant to generative AI systems.
Government Guidance
National Institute of Standards and Technology, 2024
An international requirements standard for establishing, implementing, maintaining and continually improving an Information Security Management System.
Technical Standard
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable, 2022
A structured cloud-security assurance framework and associated consensus assessment questionnaire.
Practitioner Reference
Cloud Security Alliance, 4.1, 2026
Records carry more than one topic where more than one applies. Nothing is forced into a single exclusive category.
Showing 24 of 24 records
2026
Preprint / Working Paper
Short-term productivity or time-to-prototype gains were reported in 21 of the 47 included sources.
arXiv
2026
Conference Paper
The lower-experience-proxy group submitted 2.15 times more commits per pull request.
23rd International Conference on Mining Software Repositories (MSR 2026), Mining Challenge
2025
Industry Research
AI adoption among technology professionals was high.
DORA / Google Cloud
2026
Controlled Experiment
Across the combined experiments, developers with AI assistance completed approximately 26.08% more development tasks.
Management Science
2025
Controlled Experiment
Developers took approximately 19% longer when AI tools were available in the studied setting.
METR
2025
Industry Survey
84% of respondents to the relevant question said they were using or planning to use AI tools in development.
Stack Overflow
2025
Peer-Reviewed Research
AI-generated code was generally structurally simpler and more repetitive in the studied samples.
IEEE ISSRE 2025
2026
Peer-Reviewed Research
Material CWE-mapped weaknesses were identified in the dataset.
2022
Peer-Reviewed Research
Approximately 60% of the incidents arose from infrastructure, deployment or service dependencies rather than direct code/configuration faults.
Historical
Microsoft Research, ACM SoCC 2022
2025
Peer-Reviewed Research
49.8% of the studied GenAI incidents were primarily classified as performance degradation.
Microsoft, ISSRE 2025
2026
Government Guidance
Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.
UK National Cyber Security Centre
2026
Practitioner Reference
Technical diligence can examine product capability, architecture, technology stack, technical debt, R&D organisation, open-source use, hosting, cloud, cybersecurity and scalability.
Deloitte
2021
Peer-Reviewed Research
Significant re-architecture should be informed by evidence about the actual system rather than architectural fashion or intuition.
Information and Software Technology
2025
Peer-Reviewed Research
The transition was incremental rather than a single cutover.
Carbon Health, EASE 2025
2023
Government Guidance
The framework is organised around Govern, Map, Measure and Manage.
Current, revision underway
National Institute of Standards and Technology
2024
Government Guidance
The profile addresses risks including confabulation, data privacy, information integrity, information security and component integration.
National Institute of Standards and Technology
2026
Practitioner Reference
CCM v4.1 contains 207 controls across 17 domains.
Cloud Security Alliance, 4.1
2022
Technical Standard
ISO/IEC 27001 addresses organisational information-security management.
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable
2022
Technical Standard
Assurance cases provide a structured way of connecting technical claims, arguments, evidence and assumptions.
ISO / IEC / IEEE
2026
Government Guidance
The guidance uses assurance claims rather than treating high-level principles as self-evident.
UK National Cyber Security Centre
2023
Technical Standard
The 2023 edition defines a product-quality model using nine quality characteristics.
ISO / IEC
2024
Technical Standard
Software quality evaluation is a process rather than merely a list of product characteristics.
ISO / IEC
2025
Practitioner Reference
ASVS is designed around application-security verification requirements rather than high-level awareness categories.
OWASP Foundation, 5.0.0
2022
Government Guidance
SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.
Current, revision underway
National Institute of Standards and Technology, SP 800-218, SSDF v1.1
Lornets prioritises primary technical standards, government and institutional guidance, peer-reviewed research and transparent industry evidence. Vendor and practitioner research may be included where useful and is identified by evidence type.
Source findings, Lornets interpretation and material limitations are kept distinct. Where credible evidence points in different directions, those differences are made visible rather than forced into a single conclusion.
Sources are periodically rechecked because standards, software platforms and AI engineering practices continue to change.
Evidence informs the methodology. It does not replace examination of a specific system.