Rapid creation. Thinner production evidence.
Vibe Coding in Software Development: A Multivocal Literature Review
Preprint / Working Paper / Preprint
Insights
Standards, research and industry evidence relevant to production assurance, rapidly built software and technical risk.
Lornets reviews primary research, recognised engineering standards, government guidance and transparent industry evidence. Source findings, Lornets interpretation and material limitations are kept distinct.
Filter by topic
Selecting a topic filters the full library further down this page. Select it again to clear it.
24 published evidence notes
Rapid creation. Thinner production evidence.
Preprint / Working Paper / Preprint
AI amplifies the engineering system around it.
Industry Research / DORA / Google Cloud
Production failures extend beyond source code.
Peer-Reviewed Research / Microsoft Research / ACM SoCC 2022
Migration changes the risk surface rather than simply removing it.
Peer-Reviewed Research / Carbon Health / EASE 2025
Each signal carries its source, response base, material limitation and attribution. Values are only ever taken from the published source data, and results from different questions or studies are never placed on one shared axis.
AI adoption
84%
Using or planning to use AI tools in development
n = 33,662
Trust in output accuracy
Trust
Distrust
n = 33,244
Higher-experience group = 1x
Commits per PR
Files changed per PR
Review comments
Resolution time
Acceptance rate was 31% lower for the lower-experience group.
AI-assisted development is often discussed as though it has one universal productivity effect. Current evidence indicates that the measured effect depends on the developer, task, repository, tool and outcome being measured.
Substantial gains in large field experiments
Three randomised field experiments covering 4,867 professional developers found a positive combined effect on completed development tasks.
A measured slowdown in experienced maintainers
A controlled study of experienced open-source developers working on real issues in repositories they knew well measured slower task completion when early-2025 AI tools were available.
Local development gains meet system constraints
DORA's research suggests AI acts as an amplifier of the wider engineering environment and that increased development velocity can interact with downstream delivery constraints.
The cited studies measure different outcomes and should not be presented as directly comparable effect sizes.
Standards and government guidance are held in the same evidence register as research, so a standard can be mapped to framework domains and services in the same way. Lornets does not reproduce copyrighted standards material and is not certified by or affiliated with these organisations.
ISO / IEC, 2023
The current ISO SQuaRE product-quality model for specifying and evaluating ICT product quality.
Technical Standard
ISO / IEC, 2024
A current ISO SQuaRE standard covering the framework, concepts, requirements and process for evaluating ICT product, data and service quality.
Technical Standard
ISO / IEC / IEEE, 2022
A standard specifying requirements for the structure and terminology of assurance cases.
Technical Standard
UK National Cyber Security Centre, 2026
UK government software-assurance guidance decomposing software-security principles into claims that should be supported by appropriate evidence.
Government Guidance
OWASP Foundation, 5.0.0, 2025
A structured application-security verification standard containing concrete requirements for assessing technical security controls.
Practitioner Reference
National Institute of Standards and Technology, SP 800-218, SSDF v1.1, 2022
A risk-based set of secure software-development practices intended to be integrated into software-development lifecycles.
Current, revision underway
Government Guidance
National Institute of Standards and Technology, 2023
A voluntary risk-management framework for organisations designing, developing, deploying or using AI systems.
Current, revision underway
Government Guidance
National Institute of Standards and Technology, 2024
A Generative AI profile extending the NIST AI Risk Management Framework with risks and actions particularly relevant to generative AI systems.
Government Guidance
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable, 2022
An international requirements standard for establishing, implementing, maintaining and continually improving an Information Security Management System.
Technical Standard
Cloud Security Alliance, 4.1, 2026
A structured cloud-security assurance framework and associated consensus assessment questionnaire.
Practitioner Reference
Records carry more than one topic where more than one applies. Nothing is forced into a single exclusive category.
Showing 24 of 24 records
2026
Preprint
Short-term productivity or time-to-prototype gains were reported in 21 of the 47 included sources.
2026
MSR 2026
The lower-experience-proxy group submitted 2.15 times more commits per pull request.
2025
DORA / Google Cloud
AI adoption among technology professionals was high.
2026
Management Science
Across the combined experiments, developers with AI assistance completed approximately 26.08% more development tasks.
2025
METR
Developers took approximately 19% longer when AI tools were available in the studied setting.
2025
Stack Overflow
84% of respondents to the relevant question said they were using or planning to use AI tools in development.
2025
IEEE ISSRE 2025
AI-generated code was generally structurally simpler and more repetitive in the studied samples.
2026
Material CWE-mapped weaknesses were identified in the dataset.
2022
Microsoft Research, ACM SoCC 2022
Approximately 60% of the incidents arose from infrastructure, deployment or service dependencies rather than direct code/configuration faults.
Historical
2025
Microsoft, ISSRE 2025
49.8% of the studied GenAI incidents were primarily classified as performance degradation.
2026
UK National Cyber Security Centre
Supplier assurance can include governance, incident recovery, cloud configuration, privileged access, bespoke software security, data handling, testing and certification.
2026
Deloitte
Technical diligence can examine product capability, architecture, technology stack, technical debt, R&D organisation, open-source use, hosting, cloud, cybersecurity and scalability.
2021
Information and Software Technology
Significant re-architecture should be informed by evidence about the actual system rather than architectural fashion or intuition.
2025
Carbon Health, EASE 2025
The transition was incremental rather than a single cutover.
2023
National Institute of Standards and Technology
The framework is organised around Govern, Map, Measure and Manage.
Current, revision underway
2024
National Institute of Standards and Technology
The profile addresses risks including confabulation, data privacy, information integrity, information security and component integration.
2026
Cloud Security Alliance, 4.1
CCM v4.1 contains 207 controls across 17 domains.
2022
ISO / IEC, 2022 edition, with Amendment 1:2024 applicable
ISO/IEC 27001 addresses organisational information-security management.
2022
ISO / IEC / IEEE
Assurance cases provide a structured way of connecting technical claims, arguments, evidence and assumptions.
2026
UK National Cyber Security Centre
The guidance uses assurance claims rather than treating high-level principles as self-evident.
2023
ISO / IEC
The 2023 edition defines a product-quality model using nine quality characteristics.
2024
ISO / IEC
Software quality evaluation is a process rather than merely a list of product characteristics.
2025
OWASP Foundation, 5.0.0
ASVS is designed around application-security verification requirements rather than high-level awareness categories.
2022
National Institute of Standards and Technology, SP 800-218, SSDF v1.1
SSDF organises secure-development practices into a structured set of outcomes rather than prescribing one development methodology.
Current, revision underway
Lornets prioritises primary technical standards, government and institutional guidance, peer-reviewed research and transparent industry evidence. Vendor and practitioner research may be included where useful and is identified by evidence type.
Source findings, Lornets interpretation and material limitations are kept distinct. Where credible evidence points in different directions, those differences are made visible rather than forced into a single conclusion.
Sources are periodically rechecked because standards, software platforms and AI engineering practices continue to change.
Evidence informs the Lornets Production Assurance Methodology. It does not replace direct examination of a specific system: a conclusion about your software comes from your context, your evidence and structured senior engineering judgement.