Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ShipReady Metrics track AI-generated code?

Updated

It measures a git-marker floor for the share of merged lines authored by AI, reconciles it against a figure your team types, and meters per committer. No article of Regulation (EU) 2024/1689 requires this. It is engineering-governance signal. Not legal advice.

AI-authored code measurement, last verified 10 September 2026. This is a ShipReadyMetrics engineering capability, not an obligation under Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). No article of that Regulation requires an organisation to measure how much of its source code an AI assistant wrote. NIST AI RMF 1.0 and secure-software-development guidance are guidance, not law. ISO/IEC 42001:2023 is a standard, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk.

This is engineering governance, not an AI Act obligation

Audience: an engineering leader, CTO, or head of platform who wants to know how much of the codebase an assistant wrote, who is using assistants, and what that changes about review and risk. This page is not legal advice. It does not start a clock. Nothing here is a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk.

State the important part first: measuring AI-authored code is not an EU AI Act legal requirement. Regulation (EU) 2024/1689 regulates AI systems and general-purpose AI models placed on the Union market or put into service — it does not ask how a company's own source code was typed. Using an assistant to write an internal service does not, on its own, make that service an AI system in scope, and a high AI-authored share is not a regulatory finding. This page exists inside the EU AI Act cluster because that is where the question gets asked, not because the Act asks it. Last verified 10 September 2026. Not legal advice.

  • Four kinds of text appear here, and they are labelled: legal requirements of 2024/1689 (only if they apply — and none of them is 'measure your AI-authored share'); ISO/IEC 42001:2023, a standard, not a legal substitute for the Act; NIST AI RMF 1.0 and secure-development guidance, which are guidance, not law, as are Commission AI Act pages and AI Office materials — guidance, not the regulation; and ShipReadyMetrics capability, which describes shipped behaviour and never a legal determination.
  • The engineering case stands on its own: if a growing share of merged code comes from an assistant, the review, testing, and ownership assumptions built for human-written code are quietly being asked to carry something they were not designed for. That is worth measuring whether or not any regulation ever mentions it.
  • The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. The DORA metrics glossary entry on this site covers the delivery metrics this sits beside. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

What is measured, and how

The measurement is deliberately conservative: it is a floor, derived from markers in commit history, not an estimate of how much of each line an assistant contributed. Last verified 10 September 2026. Not legal advice.

AI-authored code measurement as shipped (ShipReadyMetrics capability; not an AI Act requirement; not legal advice)
MetricWhat it isWhat it is notKind of text
Measured AI-authored share (the git-marker floor)The share of merged lines over a recent window, across the repositories that synced, attributable to AI — commits carrying an explicit AI marker, plus every commit by an AI-native author, meaning anyone who has authored an AI-marked commit.Not a precise attribution of authorship per line, and not a ceiling. Inline assistant autocomplete by an author who has never produced an AI-marked commit leaves no marker and is counted as non-AI.ShipReadyMetrics capability. No article of 2024/1689 requires it.
Declared AI-authored shareThe authoritative figure a team enters in AI ROI Inputs, shown alongside the marker-derived floor so the two can be compared rather than silently merged.Not a measurement. It is a human declaration, and it is displayed as one, with the independently measured floor beside it.ShipReadyMetrics capability.
Measured share trendThe same git-marker floor at each recently synced day, so the direction is visible rather than a single snapshot.Not the AI return-on-investment adoption grade, which is a different number on a different scale.ShipReadyMetrics capability.
AI return-on-investment scoringA view that sets adoption alongside delivery and quality signals, so that a rising assistant share can be read against what actually shipped.Not a financial audit, not a productivity verdict on individuals, and not a regulatory metric.ShipReadyMetrics capability and industry practice.
Per-committer meteringAttribution at the committer level, which is what makes AI-native authorship detectable at all.Not a performance-management tool. Using authorship attribution to rank people is a choice an organisation makes, and a bad one; the signal is about the codebase, not the person.ShipReadyMetrics capability. Employment and data-protection law govern what an employer may do with it — a legal question for counsel, not a product setting.
What is excluded from the measurement entirelyAutomated or generated commits marked to skip continuous integration, and dependency or maintenance bots such as Dependabot and Renovate, are excluded rather than counted on either side.Not a silent adjustment. The exclusions are stated on the report so the attribution stays auditable.ShipReadyMetrics capability.
Not measured yetBefore a repository sync there is no floor, and the report says so.Never a zero and never a pass. Nothing measured is reported as nothing measured.ShipReadyMetrics capability.

Example metrics — an illustration, not a benchmark

The figures below are made up to show the shape of the report. They are not data about any organisation, not an industry benchmark, and not a target. This page does not publish a benchmark for AI-authored share, because a number without a named source is a fabricated statistic. Last verified 10 September 2026. Not legal advice.

Illustrative report shape (invented figures for illustration; not a benchmark; not legal advice)
ReadingIllustrative valueHow to read itKind of text
Measured AI-authored shareA floor derived from markers across the synced repositories, shown as a share of merged lines.A floor. The true figure is at least this, and probably higher, because unmarked assistant use is invisible.ShipReadyMetrics capability. Not an AI Act metric.
Declared share, typed by an engineering leaderHigher than the measured floor, because the team knows about assistant use that leaves no commit marker.A declaration corroborated by an independent floor. The gap between them is the interesting part, not either number alone.ShipReadyMetrics capability. A human declaration, labelled as one.
Trend across recently synced daysRising.A prompt to check whether review capacity, test coverage, and ownership have moved with it. It is not a problem by itself.ShipReadyMetrics capability.
AI-native authors as a fraction of active committersA minority of committers, producing a larger share of merged lines.A concentration signal: a small group's habits are shaping the codebase. Worth a conversation, not a policy written overnight.ShipReadyMetrics capability.
What none of these readings meanNothing about EU AI Act scope, tier, or conformity.A codebase with a high AI-authored share is not thereby a high-risk AI system, and a codebase with a low one is not thereby out of scope. Not a determination that the Act applies to YOU or that YOUR system is high-risk.ShipReadyMetrics capability. Not a legal determination.

Legal requirement versus guidance versus ShipReady capability

The table below labels each text, because this is the page on which a product signal is most likely to be mistaken for a regulatory duty. Last verified 10 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 10 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689Legal requirements about AI systems and general-purpose AI models placed on the Union market or put into service, each only if they apply. No article requires an organisation to measure how much of its own source code an assistant wrote.Does not present AI-authored-share measurement as an AI Act obligation, and does not determine that the Act applies to YOU.
Regulation (EU) 2024/1689 Article 15Legal requirement — accuracy, robustness and cybersecurity for high-risk AI systems, only if it applies. It is about the system, not about how its code was typed.Does not treat an AI-authored share as evidence for or against Article 15. A dedicated AI-cybersecurity-requirements guide is not on this site yet. Naming it is not a link.
ISO/IEC 42001:2023Best practice / standard. An AI management system standard. It governs AI systems the organisation provides or uses, not the provenance of its source code.Does not treat this measurement as an ISO 42001 control or as a certificate.
NIST AI RMF 1.0 and secure-software-development guidanceGuidance, not law. Useful context for governing assistant use inside a development process.Does not treat guidance as creating a legal duty to measure AI-authored code.
This product's AI-authored-code reportingShipReadyMetrics capability and engineering-governance signal. A conservative floor, a declared figure shown beside it, a trend, and per-committer attribution.Not an AI Act legal requirement, not a compliance control, not a productivity verdict on individuals, and not legal advice.

What to do now

This block is engineering practice, not regulatory preparation. Nothing on this page is a determination that Regulation (EU) 2024/1689 binds YOU. If you are here for the Act itself, the readiness-checklist guide on this site is the deadline-anchored Article 113 self-assessment page.

  • Read the measured floor as a floor. Unmarked assistant use is invisible to it, so the honest phrasing internally is 'at least this much', never 'exactly this much'.
  • Compare the declared figure with the measured floor rather than picking one. The distance between what a team believes and what the commit history shows is the finding.
  • Ask whether review capacity moved with the share. If a rising fraction of merged code comes from an assistant and the review process is unchanged, the assumption that a human read every line has quietly expired.
  • Do not use per-committer attribution to rank people. It exists to make AI-native authorship detectable; employment and data-protection law govern what an employer may do with it, and that is a question for counsel.
  • Keep this metric out of your AI Act evidence pack unless something specific makes it relevant. Offering a regulator a metric no article asks for invites questions you did not need to answer. The AI-audit-evidence guide on this site is the evidence-request-by-role page.

Checklist

This is a question list about engineering governance, not a determination that the Act applies to YOU. Walk the legal questions with counsel.

  • Does the EU AI Act require us to measure AI-authored code? No. No article of Regulation (EU) 2024/1689 asks for it.
  • Does a high AI-authored share make our product a high-risk AI system? No. Scope and tier turn on Articles 2, 3 and 6, not on how the code was typed.
  • Is the measured share a precise attribution? No. It is a git-marker floor, and inline autocomplete by an author with no AI-marked commits leaves no trace.
  • Do you know which figure is displayed — the declared one, the measured floor, or the return-on-investment adoption grade? They are three different numbers.
  • Has review capacity, test coverage, or ownership changed as the share moved?
  • Is per-committer attribution being used for anything an employment lawyer would want to hear about first?
  • Does connecting a repository start any regulatory clock? No. This product does not start a clock and does not file with anyone.
  • Document the decision about what this metric is used for internally. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The AI-authored-code report lives in the signed-in app under Reports, not under Compliance. It is measured from synced commit history; before a sync it reads not measured yet rather than zero. The declared figure is typed by an owner in AI ROI Inputs and is displayed as a declaration beside the marker-derived floor.

The bundled framework key eu_ai_act is customer-visible and unrelated to this report. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset), the control-set is a starter subset to be tailored by a compliance owner, and marking it in-scope is not applicability. The AI inventory and the AI risk register live at signed-in app → Compliance → AI governance, a different surface from this one.

This product does not file with the AI Office, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. The cyber risk register lives under Security. ShipReady Passport is a shareable posture snapshot, not legal conformity.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 10 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. Product claims describe shipped behaviour, and the illustrative figures above are labelled as invented for illustration. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act) is a legal requirement only if it applies, and contains no duty to measure the AI-authored share of an organisation's source code. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) and secure-software-development guidance are guidance, not law. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The how-shipreadymetrics-supports-ai-governance guide on this site is the product map. The readiness-checklist guide on this site is the deadline-anchored Article 113 self-assessment page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. The DORA metrics glossary entry on this site is live. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated description of an engineering measurement, with the regulatory context stated so it is not mistaken for one. Regulation (EU) 2024/1689 contains no duty to measure AI-authored code. Whether the Act applies to YOU, and what any obligation requires, are legal questions for counsel on your facts. This page does not start a clock.

Does the EU AI Act require us to track AI-generated code?

No. Regulation (EU) 2024/1689 regulates AI systems and general-purpose AI models placed on the Union market, put into service, or whose output is used in the Union. No article of it asks how much of an organisation's own source code an assistant wrote. Measuring it is engineering governance and secure-development practice — worth doing on its own merits, and not a legal requirement of the Act.

Does a high AI-authored share make our software high-risk under the Act?

No. Whether a system is high-risk turns on Article 6 with Annexes I and III, applied to the system's intended purpose — not on how its code was written. A codebase with a large assistant contribution is not thereby in scope, and one with none is not thereby out of scope. This page does not determine that YOUR system is high-risk, and counsel applies Articles 2, 3 and 6 to your facts.

Is the measured AI-authored share exact?

No. It is a conservative floor: commits carrying an explicit AI marker, plus every commit by an author who has produced an AI-marked commit, over merged lines in the repositories that synced. Inline assistant autocomplete by an author with no AI-marked commits leaves no marker and counts as non-AI. Automated commits and dependency bots are excluded from the measurement entirely rather than counted on either side.

Should we put this metric in our AI Act evidence pack?

Usually not. No article of Regulation (EU) 2024/1689 asks for it, and volunteering a metric a regulator did not request invites questions the organisation did not need to answer. It belongs in engineering governance — review policy, testing strategy, ownership — where it earns its keep. Counsel decides what goes into any response to a reasoned request.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.