Blog

AI Now Writes 80% of Its Own Code. Who Audits That?

Subscribe now to join the Risk Register community:

Anthropic published a piece this month that should land on every internal audit leader's desk. Not as a technology update. As a governance warning.

The claim, drawn from the company's own internal data: AI is now accelerating the development of AI. As of May 2026, more than 80% of the code merged into Anthropic's codebase was written by their model, up from low single digits before Claude Code launched in early 2025. The typical Anthropic engineer ships roughly eight times as much code per day as in 2024. The company calls the endpoint of this trend recursive self-improvement, meaning a system capable of designing and developing its own successor.

Whether the endpoint arrives is somebody else's debate. The intermediate state, where AI is already writing the code that runs the business and the controls that govern it, is the practitioner problem in front of every internal audit function today. The pace of change inside AI-enabled organizations is decoupling from the cadence at which audit functions plan, test, and report. 

That gap is AI governance. It sits squarely inside internal audit's mandate.

The Governance Problem Hiding in the Productivity Data

The Anthropic piece is, on its surface, a productivity story. Read it as an auditor and a different picture emerges.

The control environment is moving faster than the assurance cycle. Anthropic describes capability roughly doubling every few months. Internal audit plans on an annual cadence. When the thing you assure changes twice between audit committee meetings, the point-in-time assessment is stale before the binder is bound.

The doing is nearly free now. The judgment is the scarce control. Anthropic's framing is direct: producing code or running an experiment now costs almost nothing in human time. What remains in human hands is direction-setting, meaning what to build and whether to trust the result. The residual human control is judgment and review, and Anthropic reports that human review has already become the bottleneck. A bottlenecked control is a control under stress.

AI is now reviewing AI. Anthropic states that an automated model reviewer screens code changes before they merge, and that this reviewer would have caught roughly a third of the bugs behind past production incidents. That is a control. It is also a control with no independent human in the loop at the point of execution. 

That arrangement is exactly what internal audit exists to evaluate.

None of this is unique to an AI lab. It is a preview of what every organization adopting AI agents is about to face: faster change, thinner human review, and AI systems embedded inside the controls themselves. Where in your control environment is AI already reviewing AI today, and would your function know who catches the third of bugs the model misses?

Read the Quiet Part: The Builders Are Telling You the Safeguards Are Behind

The most important passage in the Anthropic piece is not the productivity data. It is the part about slowing down. Read it closely, because the people closest to this technology are saying something that should stop a board cold.

They are saying the governance and controls have not caught up to the speed of frontier development. That is the admission underneath the careful language. When the builder of a technology argues that the world should at least have the option to pause, the builder is telling you the safeguards are running behind the capability.

The logic, stated plainly because it is the whole point: They would slow down if they could. 

Anthropic argues it would be good for the world to have the option to slow or pause frontier development. You do not ask for a brake on your own work unless you are worried about the speed.

They say they can't. Not because slowing is wrong, but because a unilateral pause hands the lead to whoever refuses to pause. If the cautious stop and the reckless continue, everyone ends up less safe. So they will not slow alone.

The gap stays open. The distance between how fast the frontier moves and how slowly oversight moves behind it doesn't get closed by slowing the technology down, because slowing down is off the table. It persists. It widens.

That is the part worth being precise about. It is not the machine. It is the gap. The capability is accelerating, the people building it concede the controls have not kept pace, and the one remedy that would close the distance from the top is foreclosed by the fact that whoever refuses to slow gets the lead.

The AI Governance Question Has Changed for Boards

For a board, this changes the question. The relevant question is no longer “is our AI safe.” It is: the gap between AI capability and AI control is widening, by the admission of the people building it. What is closing that gap inside our organization?

If the honest answer is “nothing on a current cadence,” that is the finding. It belongs in front of the audit committee now, not next planning cycle.

It also points to the mechanism. If the gap cannot be closed by slowing the technology down, it can only be closed by speeding the governance up. Assurance and controls that run as fast as the thing they govern, producing evidence on demand rather than once a year. That is internal audit's job. It is the one function whose mandate is independent assurance over exactly this kind of gap.

Where the Internal Audit Standards Sit on AI, and Where They Don't

The 2024 Global Internal Audit Standards took effect on January 9, 2025, and reframed the profession around governance alignment, risk-based planning, and technology enablement. They are also the basis on which external quality assessments are now conducted. AI risk falls inside that mandate. 

Not because a rule names it, but because risk-based planning requires you to cover the risks that matter, and AI is now one of them.

Here is where it gets uncomfortable. The IIA has issued binding Topical Requirements for specific risks. Cybersecurity took effect February 5, 2026. Third-Party Risk follows September 15, 2026. More are in development. There is no AI Topical Requirement yet. The framework has not yet told internal audit how to cover AI.

That absence compounds the gap. You cannot wait to be handed an AI audit program. The risk is moving on a monthly cadence, as Anthropic's own data shows. 

Standard-setters move on a multi-year one. The space between those two clocks is the exposure, and it belongs to the function, not the framework.

How would you defend the AI section of your audit plan to the committee chair this quarter, if the only thing they know is that the framework hasn't named the risk yet?

What Internal Audit Should Do Now About AI Risk

Velocity is the risk variable. Verifiability is the test. Four actions, in order.

Shorten the assurance cadence for AI risk. Move AI coverage off the annual plan and onto a continuous or quarterly footing. The cadence of your assurance should match the cadence of the change, not the calendar.

Audit the human review control specifically. Where AI generates work that humans approve, test whether that review is real or rubber-stamped. 

Anthropic's own admission that review became the bottleneck is the tell. Review is where the risk concentrates.

Evaluate AI-in-the-controls. Where AI systems sit inside the control environment (automated code review, automated reconciliations, agentic approvals), assess whether independence, override, and exception handling actually function the way the design says they do. That is what good AI controls assurance looks like in practice.

Demand verifiable evidence, not stated intent. A control that exists on paper but cannot be independently verified is a finding. Apply that test to every AI governance claim your organization makes. 

How Cherry Hill Closes the AI Governance Gap

Most AI governance frameworks tell you what good looks like. NIST AI RMF, ISO/IEC 42001, COSO's GenAI guidance, the IIA's AI Auditing Framework, the EU AI Act. 

Every one of them defines what must be true. None of them tells you how to make it true on a Tuesday, produce the evidence, and prove it again next quarter when the model has changed.

That execution layer is the work itself, and it is what Cherry Hill builds with the audit function.

Our AI Governance & Emerging Risk practice applies framework development, compliance readiness, risk assessments, control design and monitoring, internal audit enablement, and third-party AI risk oversight against your actual environment. Each component maps back to the framework, standard, or regulation it operationalizes. It replaces none of them.

This is the direct answer to the gap the Anthropic data exposes. When the technology cannot be slowed and human review becomes the bottleneck, the only way to close the distance is assurance that runs on a repeatable cadence and produces verifiable evidence on demand.

An AI governance assessment built on this practice inventories where AI is actually used, including embedded AI in vendor tools. We test whether ownership and control are real or assumed. We evaluate the human and automated controls in the loop. The output is board-ready reporting that withstands audit committee and regulator scrutiny. 

When the path forward is to extend the function rather than receive a binder of recommendations, our internal audit co-sourcing carries the work alongside your team.

Common Questions Around AI Governance

How do I tell if my AI governance program is actually working, or just documented?

A documented program is a starting point. A working program produces verifiable evidence on demand: where AI is used (including in vendor tools), who owns it, which controls are in the loop, and what the most recent test result said. If you cannot pull that evidence in a week, the gap is operational, not strategic.

Where does AI governance sit relative to the IIA Topical Requirements?

There is no AI Topical Requirement yet. Cybersecurity is in effect as of February 5, 2026. Third-Party Risk follows September 15, 2026. AI risk falls under the 2024 Global Internal Audit Standards' risk-based planning mandate. You cover it because risk-based planning requires you to cover the risks that matter, not because a Topical Requirement names it.

What does “AI in the controls” mean in practical terms?

It means AI systems that participate in your control environment, not just AI systems your business uses. Examples: automated model reviewers that screen code changes before they merge, agentic approvals that release transactions, reconciliations driven by ML scoring. Independence, override, and exception handling all need to work for those controls to actually function.

Is co-sourcing the right answer for AI audit coverage?

It is when your team has the audit-planning ownership but not the specialist depth to execute the AI work credibly. Co-sourcing extends the function with senior practitioners who have built and tested controls in this domain. It is the wrong answer when there is no in-house owner; that situation calls for a different conversation about how the IA function is structured.

How fast should AI assurance move?

Faster than annual. Anthropic's own data shows capability roughly doubling every few months. An annual plan does not survive that cadence. Continuous or quarterly coverage on AI risk is the structure most audit functions are moving toward, with point-in-time reporting only at the audit committee cadence.

The Next Disruption Is Already on the Audit Plan

When AI builds itself and the people building it admit the controls are behind, the question for every board is plain. What is closing that gap inside our organization, and can we prove it? Internal audit should be able to answer. 

The next disruption is already on the calendar. Whether the assurance function is ready for it is the only thing left to decide.

Schedule a call to scope an AI governance assessment with Cherry Hill Advisory's AI Governance & Emerging Risk practice, or talk to us about extending the function through internal audit co-sourcing.

Until next time. 

Subscribe now to join the Risk Register community: