AI Tooling in Software Development: Productivity with Compliance in Mind
AI-assisted development can accelerate delivery, but only when productivity is balanced with compliance, review, and governance.
Original LinkedIn versionExecutive Summary
Artificial Intelligence (AI) is transforming various industries, but particularly software development at speed. In 2025, almost two-thirds of developers use AI-assisted tools such as GitHub Copilot, Amazon CodeWhisperer, JetBrains AI and Tabnine. At Microsoft, nearly 30% of all code is now AI-generated. Independent studies show that AI assistance can reduce coding time by more than 50%.
This productivity shift is undeniable. However, for organisations operating under compliance standards such as ISO 27001:2022, SOC 2 Type 2, or preparing for the requirements of the EU AI Act, adoption must be balanced with governance. The question is no longer “Should we use AI in development?” but “How do we use AI responsibly, while staying compliant?”
The Compliance Lens on AI in Development
ISO 27001: AI-generated code and documentation are part of an organisation’s information assets. If these outputs are not classified, reviewed, and secured within the Information Security Management System (ISMS), organisations risk gaps in compliance.
SOC 2 Type 2: The Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) apply equally to AI-driven processes. For instance, if AI tools recommend insecure libraries, organisations must evidence that change management and peer review processes identify and remediate the issue.
EU AI Act: Although it classifies only certain systems as “high-risk,” the Act introduces a broad expectation of transparency, accountability, and human oversight. Development teams relying on AI assistants will need to show how these principles are embedded into their workflows, even if their systems are not formally regulated as high-risk.
Emerging Themes in AI Adoption
Across the industry, three themes are consistently raised:
Productivity vs Quality
AI speeds up delivery but can introduce technical debt, security vulnerabilities, and compliance risks. Without structured oversight, organisations risk prioritising speed over resilience and accuracy.
Integrated Tooling vs Fragmentation
Scattered use of multiple AI tools complicates governance. Integrated platforms make it easier to enforce access controls, monitor usage, and demonstrate compliance.
Developer Experience and Oversight
Effective AI adoption isn’t just about efficiency; it must also support sustainable workloads and safe working practices. The EU AI Act reinforces this by requiring human oversight and explainability.
Best Practice Recommendations
To balance innovation with compliance, organisations should:
- Define Purpose First: Just Like Simon Sinek famously expouses “Start with Why”. Align AI adoption with business goals and compliance obligations, not just productivity metrics.
- Classify AI Outputs: Treat AI-generated code and artefacts as formal information assets, subject to the same policies and controls as human-created ones.
- Integrate Compliance into the Toolchain: Enable audit logging, enforce peer review and approval, and link AI tools into existing CI/CD and security pipelines.
- Maintain Human Oversight: Apply “human-in-the-loop” review processes to all AI outputs, supporting both quality assurance and EU AI Act requirements.
- Continuously Reassess Risk: Update risk registers and control frameworks to explicitly account for AI tooling, ensuring ISO 27001 and SOC 2 evidence requirements are met.
Conclusion
AI is no longer optional in modern software development. The productivity gains are clear, but the real advantage lies in responsible adoption. Organisations that integrate AI within the frameworks of ISO 27001, SOC 2 Type 2, and the EU AI Act will not only accelerate delivery but also strengthen trust with auditors, regulators, and customers.
AI should not be viewed as a shortcut to faster development—it should be seen as a lever for building secure, compliant, and future-proof software practices.