AI agent coding compliance

Standards your AI agents
can actually follow.

When AI writes code at production scale, your standards have to be something an agent can read. Code Standards packs put ISO, OWASP, regulatory and in-house engineering rules in front of your coding agents, from copilots through to autonomous agents, as they write. Human review still matters; it starts from code written to the rules.

What's in the box

01

Pre-built standards packs

50+ pre-built packs: ISO 25010, 27001, 42001, OWASP Top 10 / ASVS, PCI-DSS, NIST, GDPR and language style guides, written for your agents to read directly.

02

Bespoke in-house rulesets

Codify your architecture rules, security posture and house style into machine-readable skills, layered on top of any standards pack. Your agents follow both together.

03

Regulated-domain coverage

Medical-device safety (ISO 14971), automotive (ISO 26262), accessibility (WCAG 2.2), payments (PCI-DSS), data (UK GDPR) — full-spectrum.

04

Continuous standards updates

Standards bodies move; your skills packs move with them. Packs are actively maintained, versioned and updated as standards change.

05

Audit-ready provenance

Every rule traces back to a specific clause in a published standard. When an auditor asks why your code does something, the answer is the clause that requires it, not "because an AI suggested it".

06

Enterprise rollout

Works with Claude, GitHub Copilot, Cursor and other agents that read structured rules. One set of rules across the tools your team already runs, designed for organisations, not single developers.

07

Framework-aware rules

A generic "use parameterised queries" rule is useless if your agent does not know whether you are in Laravel, Django or Express. Packs are framework-specific: how your ORM works, where middleware sits, what your testing conventions look like.

08

Drift detection

Alerts when agent output starts to deviate from your defined standards, whether the cause is a model update, a context window change or a prompt modification.

09

Assess an existing codebase

Already have the code? We assess it against any combination of standards and report the gaps, file by file, with prioritised remediation guidance.

Standards covered

Packs are written from the full specification of each standard. Names only here; the detail is on the Digital Tactics product page.

ISO
ISO 25010, ISO 27001, ISO 9001, ISO 12207, ISO 15408, ISO 25023, ISO 42001, ISO 14971, ISO 26262
Security and compliance
OWASP Top 10, OWASP ASVS, PCI-DSS, NIST SP 800-53, CWE / SANS Top 25, GDPR and UK GDPR
Language and framework
PSR-1/4/12, PEP 8 / PEP 257, ECMAScript / TypeScript, Go, Rust, C#
Accessibility and sustainability
WCAG 2.2, Software Carbon Intensity (SCI), EU AI Act
Sector-specific
Automotive (ISO 26262 / ASPICE), aerospace (DO-178C / DO-326A), medical (IEC 62304 / ISO 14971), defence (DEF STAN / MIL-STD), rail (EN 50128 / CENELEC), financial (SOX / MiFID II / Basel)

Why not a free rules file?

Free rules files exist, and they are a starting point. Public repos typically paste a standard's table of contents into a prompt; Code Standards packs are written from the full specification, as rules an agent can apply. Open source rules are often abandoned after their first commit, which leaves your agents working to outdated guidance; our packs are maintained and versioned. And a one-size-fits-all file knows nothing about your house rules, so we layer your own conventions on top.

Built for teams shipping at AI scale.

"AI agents generate code at extraordinary speed. Without standards enforcement, that speed becomes a liability."

Chris Dean, CEO and Founder, Digital Tactics

Code Standards is a Digital Tactics product. We work with engineering and security leadership to roll it out across copilots, agent platforms and CI pipelines — and stay close while the standards landscape keeps moving.

Need a skill on something other than coding standards? Our sister site Skill Publisher writes skills to order on any subject.

Common questions

Who is Code Standards for?

Engineering and security teams whose developers are now using AI agents (Copilot, Cursor, Claude Code, internal agents) at scale. Code Standards puts your engineering, security and regulatory rules in front of those agents as they write, so review starts from code written to the rules.

Which AI tools and agents does it work with?

Claude, GitHub Copilot, Cursor and other agents that read structured rules. The skills packs are tool-agnostic: plain files in an open format, so there is no one-vendor lock-in.

Can it cover our own internal or proprietary standards?

Yes. Bespoke skills packs are a core mode. We codify your architecture rules, security posture, naming conventions, framework choices and house style into machine-readable skills, layered on top of the public ISO, OWASP and regulatory packs. Your agents follow both together.

Is the standards library kept up to date?

Yes. Standards bodies move (OWASP rotates, ISO revises, regulators add) and the skills packs move with them. Packs are actively maintained, versioned and dated.

What happens when standards overlap or conflict?

Real codebases operate under multiple overlapping standards: ISO 25010, OWASP, PCI-DSS and your own house rules. Code Standards packs resolve conflicts and define precedence, so your agents do not generate contradictory code or silently ignore one standard in favour of another.

What evidence can we show an auditor?

Every rule traces back to a specific clause in a published standard. When a regulator or auditor asks why your code does something, the answer is documented: the clause that requires it, not "because an AI suggested it". Drift detection adds an alert when agent output starts to deviate from your defined standards.

What if we need a skill on something other than coding standards?

Our sister site, Skill Publisher, writes a skill to your brief on any subject, at a fixed price, ordered online at skillpublisher.com. Both deliver skills in the same open format.