arXiv: The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents
AI Analysis
This paper, published on arXiv in August 2026, identifies a systemic gap in how AI coding agents are governed under current EU regulatory frameworks. It argues that these agents can introduce vulnerabilities that do not map cleanly to existing CVE (Common Vulnerabilities and Exposures) reporting mechanisms, creating a blind spot where security flaws persist without a formal identifier. The authors highlight a mismatch between regulatory mandates, such as those under the EU AI Act and Cyber Resilience Act, and the actual authority of auditors or developers to enforce fixes, particularly when the agent’s behavior is emergent or non-deterministic.
The primary affected parties are organizations deploying AI-assisted software development, including technology firms, financial services, healthcare, and any sector relying on automated code generation. Also impacted are conformity assessment bodies and internal compliance teams that must verify AI system safety but lack clear technical standards for evaluating coding agent outputs. Regulators and national supervisory authorities will face challenges in enforcing accountability when no single party controls the full software supply chain.
Compliance teams should immediately inventory all AI coding tools in use and map their outputs to existing vulnerability management processes, noting where CVE assignment fails. They should document these gaps in their risk registers and align with the EU AI Act’s transparency and human oversight obligations by implementing mandatory human review for high-risk code changes. Next, they should engage with industry working groups on AI security to advocate for interim reporting standards, and prepare internal escalation protocols for vulnerabilities that lack CVEs, ensuring they are tracked and remediated with the same rigor as formally identified flaws.
Get notified about AI_SAFETY changes
Subscribe to our free weekly digest covering 24 compliance frameworks.