Source-linked AI summary

AI Policies: Help or Hindrance? A Software Developer's Perspective

Samuel Ferino, Rashina Hoda, John Grundy, Christoph Treude, Hashini Gunatilake

arXiv:2609.16496v1cs.SEcs.AI

TL;DR

Organisations introduce AI policies to mitigate LLM-related risks, but evidence about how those policies affect software developers remains limited. This study analyses 19 developer interviews to examine how policies help and hinder developers. It identifies an evolution from strict prohibitions toward licensed access and supports developer-centric guidance for managers and decision makers.

  • Problem

    Developer perspectives are critical because governance and policy cannot help if developers do not engage with organisational LLM policies.

  • Method

    The study analyses semi-structured interviews with 19 software developers using socio-technical grounded theory for data analysis.

  • Results

    The study finds that permissive and prohibitive policies are both a help and a hindrance, with some organisations progressing from strict prohibitions toward licensed LLM access.

  • Takeaways & Limitations

    Managers and decision makers should use a developer-centric approach, including clear boundaries, safeguards, training, and responsibilities for LLM use.

  • Takeaways & Limitations

    The study has a modest sample of 19 practitioners, limited experience under prohibitive policies, and potential self-selection bias.

Abstract

from arXiv · show

AI policies introduced by software organisations to mitigate LLM-related risks such as sensitive information leaks and unauthorised usage are not useful if software developers do not engage with them. We draw on 19 software developer interviews to show how AI policies help and hinder developers. We suggest approaches to support managers and decision makers with a developer-centric approach to introducing AI policies.

Introduction

AI adoption offers substantial productivity value, but security and governance concerns remain significant. Organisations therefore need to balance risk mitigation with the costs and disruption that policy changes can impose on developers.

  • 88% of early LLM adopters report positive ROI and 70% cite immediate productivity gains, while security and risk concerns remain the main barrier to scaling AI.
  • Only 21% of companies maintain mature governance frameworks for autonomous AI agents, leaving risks around data privacy and unmonitored employee AI use.
  • Introducing or updating AI policies, structures, and workflows can require substantial time and financial resources and disrupt software development processes.
  • The study uses empirical findings to identify what helps and hinders software developers and support managers and decision makers navigating AI policies.

Methodology

The study describes how organisations govern LLM adoption through prohibitions, permissions, uncertainty, and evolving controls, with each approach creating both benefits and burdens for developers. Developers value access and productivity but also need clear boundaries addressing security, confidentiality, ownership, and responsible use.

  • Organisational Policies for Governing LLM Adoption: Organisations use four policy states: allowing LLMs, prohibiting them, having no policy, or leaving employees unsure of the organisational stance.
  • Organisational Policies for Governing LLM Adoption: Some organisations evolve incrementally from complete prohibition toward permitting licensed LLMs, while others defer policy development because business value and product-release priorities remain uncertain.
  • Organisational Policies for Governing LLM Adoption: Licensed LLMs, private APIs, prompting guidelines, monitoring, and explicit usage declarations are used to enable controlled adoption and mitigate data leakage and unauthorised training.
  • How do Policies Help?: Prohibitive policies can avoid non-deterministic outputs, third-party dependency, and security exposure, but may constrain coding work and reduce perceived innovation and productivity.
  • How do Policies Help?: Permissive policies help developers automate coding and non-coding tasks, including meeting summarisation and codebase onboarding, while enterprise agreements can prevent submitted data from being used for training.
  • How do Policies Help?: Unclear boundaries leave developers uncomfortable about sending proprietary or sensitive code, making explicit definitions of allowed data and tools important to policy engagement.

Conclusion

The study finds that both permissive and prohibitive LLM policies can help and hinder software developers, and recommends evolving governance toward permissive access once identified gaps are addressed.

  • Conclusion: AI governance can progress from strict LLM prohibitions toward permissive access through licensed LLMs, except in exceptional cases.
  • Conclusion: Permissive and prohibitive policies each have a two-sided effect, helping and hindering software developers.
  • Conclusion: Managers can use actionable recommendations and a policy progression checklist to mitigate policy-related hindrances.
  • Conclusion: The checklist asks organisations to assess safeguards, training, sensitive-information definitions, developer risk awareness, privacy policies, and code ownership.

Recommendations for Future Research

The paper identifies future research questions about developers’ interpretation of AI policies and organisations’ ability to monitor responsible adherence during software work.

  • Recommendations for Future Research: Future research should examine how accurately software developers interpret organisational AI policies and where manager intent differs from developer understanding.
  • Recommendations for Future Research: Future research should investigate how organisations can monitor responsible AI adherence during software work.
Loading 2609.16496v1…