Disclaimer
This is a draft discussion paper circulated for peer review. It is independent work published in a personal capacity and does not constitute official guidance or policy of any government body. It does not mandate or recommend specific controls for any agency, system, or project. Views and analysis are the author's own.
About This Project¶
| Field | Value |
|---|---|
| Version | 0.1.0 |
| Status | Draft for Comment |
| Date | 24 March 2026 |
| Prepared by | John Morrissey |
This site hosts the discussion paper suite Semantic Defects in AI-Generated Code: Assurance Frameworks for AI-Assisted Development in High-Stakes Code Paths — a body of work examining how AI coding tools produce code that is syntactically correct and passes automated checks but makes wrong decisions about data that matters in institutional contexts.
The document suite¶
The suite comprises the documents below, which present one argument at different depths. PDF versions are available for offline reading and distribution.
| Document | Audience | What it covers | |
|---|---|---|---|
| Understanding AI Code Risk (~13 pp) | Everyone | The problem statement: what the defects are, why they are not targeted by existing checks, why updated assurance is needed. Entry point for all other reading. | |
| Reviewing AI-Generated Code: A Practical Guide (~23 pp) | Staff using AI to write code | Five review questions, worked code examples, hot-path identification — for people copying code from AI chat windows without CI or developer tooling. | |
| Discussion Paper (~200 pp) | Technical leads, assessors, security architects | Full analysis: failure taxonomy (ACF — 15 core entries, 5 provisional), STRIDE mapping, case studies, annotated agent transcript, cross-model defect chaining, systems thinking primer. v0.1.0. |
Document Suite Map (PDF) — a one-page reading path guide routing nine roles to the right document.
Key entry points¶
- The accessible argument — the problem statement in plain language
- Practical guide for code authors — hands-on review guidance for staff using AI to write code
- Full discussion paper — complete technical analysis and evidence base
Disclaimer¶
This is an independent draft discussion paper, written and published in a personal capacity. It does not constitute official guidance or policy of any government body. Views and analysis are the author’s own.