This paper, published on arXiv, introduces a new benchmark called Adaptive Adversaries designed to test the security of large language model (LLM) agents. Unlike previous single-turn tests, this…
arXiv: Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation
AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.
AI Analysis
What changed and what to do.
A new preprint from arXiv, titled "Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation," published on 20 July 2026, presents evidence that large language models (LLMs) used for code generation can develop persistent, insecure coding preferences stored in their long-term memory. This means that even after initial safety training, an LLM may consistently produce code with vulnerabilities, such as SQL injection or buffer overflow risks, because these insecure patterns become embedded in the model's underlying weights. The paper highlights that this is not a transient error but a systemic bias that can be difficult to detect or correct through standard prompt engineering.
This finding directly affects any organization deploying LLM-based code generation tools, particularly in regulated sectors such as finance, healthcare, critical infrastructure, and software development firms subject to EU AI Act or NIS2 requirements. Compliance teams in these sectors must reassess their AI supply chain risk management, as the insecure coding preferences could lead to widespread deployment of vulnerable software, increasing liability and regulatory exposure.
Compliance teams should immediately review their AI model validation procedures to include adversarial testing for persistent insecure coding patterns, not just functional accuracy. They should also update their vendor due diligence questionnaires to require evidence that LLM providers test for and mitigate long-term memory biases. Finally, teams should document these risks in their AI risk registers and prepare for potential updates to internal code review processes, ensuring that all AI-generated code undergoes mandatory security scanning before deployment.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More AI_SAFETY updates
Latest in AI_SAFETY.
This paper, published on arXiv, proposes a new technical framework for generating synthetic data that is specifically designed to preserve privacy while maintaining domain-specific utility. It…
A new research paper published on arXiv on July 20, 2026, titled "Self-State Attacks on Self-Hosted AI Agents: How Far Can OS Defenses Go?" examines vulnerabilities in self-hosted AI agents where an…
This publication introduces a new technical framework, RT-SHCUA, which enables real-time, self-hosted control of unmanned aerial vehicles (UAVs) through an artificial intelligence agent. The system…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.