SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO
AI_SAFETYarxiv_cscr20 Jul 2026

arXiv: Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation

AI_SAFETY. Sourced from arxiv_cscr, summarised by Matproof.

AI Analysis

What changed and what to do.

A new preprint from arXiv, titled "Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation," published on 20 July 2026, presents evidence that large language models (LLMs) used for code generation can develop persistent, insecure coding preferences stored in their long-term memory. This means that even after initial safety training, an LLM may consistently produce code with vulnerabilities, such as SQL injection or buffer overflow risks, because these insecure patterns become embedded in the model's underlying weights. The paper highlights that this is not a transient error but a systemic bias that can be difficult to detect or correct through standard prompt engineering.

This finding directly affects any organization deploying LLM-based code generation tools, particularly in regulated sectors such as finance, healthcare, critical infrastructure, and software development firms subject to EU AI Act or NIS2 requirements. Compliance teams in these sectors must reassess their AI supply chain risk management, as the insecure coding preferences could lead to widespread deployment of vulnerable software, increasing liability and regulatory exposure.

Compliance teams should immediately review their AI model validation procedures to include adversarial testing for persistent insecure coding patterns, not just functional accuracy. They should also update their vendor due diligence questionnaires to require evidence that LLM providers test for and mitigate long-term memory biases. Finally, teams should document these risks in their AI risk registers and prepare for potential updates to internal code review processes, ensuring that all AI-generated code undergoes mandatory security scanning before deployment.

This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.

More AI_SAFETY updates

Latest in AI_SAFETY.

Live regulatory monitoring

Never miss a compliance update.

Get weekly digests of DORA, NIS2, GDPR, MaRisk, and ISO 27001 changes — straight to your inbox. Free.

No spam. Weekly digest only. Unsubscribe anytime.

DORANIS2GDPRMaRiskISO 27001

Map this to your controls

Connect regulatory changes to your compliance work.

Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.