{
  "source": "Cooked Index — occupational AI risk register",
  "page": "https://cookedindex.com/jobs/software-developers/",
  "methodology": "https://cookedindex.com/methodology",
  "notice": "Verdicts are re-examined as evidence accumulates. Re-fetch before relying on this; the page above always carries the current score.",
  "scored_at": "2026-08-11",
  "model": "claude-opus-5",
  "occupation": {
    "title": "Software Developers",
    "soc_code": "15-1252",
    "category": "Tech",
    "us_employment": 1687890,
    "median_annual_wage": 135980
  },
  "verdict": "EXPOSED",
  "risk_resistance": 41,
  "contested": false,
  "near_boundary": false,
  "dimensions": {
    "task_resistance": 11,
    "embodiment": 3,
    "liability_shield": 3,
    "trust_premium": 9,
    "judgment_accountability": 15
  },
  "reasoning": {
    "task_resistance": "An 11 reflects the split week: ticket-to-PR work, test scaffolding, API glue, and framework migrations are now draftable in minutes, but the parts that eat the other half of your time — reproducing an intermittent race condition in a distributed system, reading a decade of undocumented business logic to figure out why the invoice total is off by a cent, and deciding which of four broken proposals to ship before quarter-end — still need someone holding the whole system in their head.",
    "embodiment": "A 3 rather than 0 because on-prem deploys, hardware-in-the-loop debugging, and embedded or firmware work put some developers next to physical devices, but the median job is a laptop, an IDE, and a Slack window from anywhere with WiFi.",
    "liability_shield": "A 3 is where no-licence sits: there is no PE stamp for most software in the US, no bar admission, no statutory sign-off, and CI/CD means a broken commit gets reverted rather than litigated — the employer's EULA disclaims warranty and the company, not you, absorbs the outage.",
    "trust_premium": "A 9 covers what actually holds: users never meet you and your commits are interchangeable to them, but your product manager, on-call rotation, and the two colleagues who know why the payments service is shaped that way rely on accumulated trust and context that a fresh contractor or a model prompt cannot inherit in a sprint.",
    "judgment_accountability": "A 15 is earned by the calls with no runbook — approving a schema migration on a live table, choosing to log or not log a field that turns out to be PII, deciding at 3am whether to roll back or forward, and setting an architecture that either scales or gets rewritten in two years — decisions where you are named in the postmortem and the cost is measured in revenue or breached records."
  },
  "rationale": "Writing functions, unit tests, boilerplate CRUD endpoints, and translating a ticket into a pull request are exactly what coding models do well now, and that is a large share of the median developer's week. What persists is deciding what to build under vague requirements, owning a production system at 3am, negotiating tradeoffs across teams, and being the person accountable when a design choice costs money or leaks data. The occupation splits: the junior implementation tier compresses hard, the systems-and-accountability tier holds, and no license protects either side.",
  "outlook": "By 2035 the job title survives but the headcount pyramid inverts — far fewer people paid to type code, more paid to specify, review, and own systems, with entry-level hiring the hardest hit.",
  "what_would_raise_it": {
    "levers": [
      {
        "dimension": "task_resistance",
        "change": "Task-mix shift is real here: as ticket-to-PR work is automated, the residual job becomes architecture, incident forensics, cross-service migration under legacy constraints, and reviewing/verifying machine-written diffs at scale. If the median role effectively becomes review-and-integrate of AI output plus system design, measured resistance of the remaining day rises even with no new capability limit — visible already in the collapse of junior openings versus stable senior/staff demand.",
        "plausibility": "already happening",
        "would_add": 4
      },
      {
        "dimension": "liability_shield",
        "change": "Sector-specific attestation regimes that name an individual engineer: the EU Cyber Resilience Act (obligations phasing to 2027) plus CISA's Secure Software Development Attestation Form, which requires a named company officer to attest to SSDF practices for software sold to the US federal government. If attestation devolves to a named responsible engineer with personal exposure — or if a licensure scheme like the (currently withdrawn in most states) PE Software Engineering exam is revived for safety-critical systems such as medical device firmware, avionics, or voting systems — a signature requirement appears where none exists.",
        "plausibility": "plausible",
        "would_add": 4
      },
      {
        "dimension": "liability_shield",
        "change": "FDA Software as a Medical Device and DO-178C/FAA airworthiness pathways already require named individuals to sign verification records for a narrow slice of developers. If FDA guidance on AI-enabled device software function requires human-identified authorship and sign-off on model-generated code changes in premarket submissions, that slice widens.",
        "plausibility": "plausible",
        "would_add": 2
      },
      {
        "dimension": "judgment_accountability",
        "change": "Formalized on-call and postmortem accountability tied to regulatory incident reporting — SEC Item 1.05 cybersecurity material-incident disclosure within four business days, and EU NIS2 24-hour reporting — makes the engineer who owns the system the person whose call is documented in a filing. If firms respond by naming system owners of record for critical services, the ambiguity-ownership component hardens.",
        "plausibility": "already happening",
        "would_add": 2
      },
      {
        "dimension": "trust_premium",
        "change": "Narrow route only: procurement and insurance language demanding provenance. Cyber insurers and enterprise vendor questionnaires increasingly ask whether AI-generated code entered the codebase, and some contracts (and license-contamination fears after the GitHub Copilot litigation) require warranty that code is human-authored or human-reviewed with named reviewers. That is willingness to pay for human authorship, but it is contractual rather than consumer taste, and it caps low.",
        "plausibility": "plausible",
        "would_add": 2
      }
    ],
    "ceiling_note": "No realistic route to a broad consumer trust premium — buyers of software want the artifact, not a human's hand in it, and no client asks who typed the function. Embodiment has no route. Even with attestation regimes, licensure would cover a small safety-critical minority; the bulk of the occupation remains unshielded, and the compressing junior tier gains nothing from any of these levers."
  },
  "adjudication": null,
  "employment_history": {
    "points": [
      {
        "y": 2021,
        "emp": 1364180,
        "wage": 120730
      },
      {
        "y": 2022,
        "emp": 1534790,
        "wage": 127260
      },
      {
        "y": 2023,
        "emp": 1656880,
        "wage": 132270
      },
      {
        "y": 2024,
        "emp": 1654440,
        "wage": 133080
      },
      {
        "y": 2025,
        "emp": 1687890,
        "wage": 135980
      }
    ],
    "from": 2021,
    "to": 2025,
    "change_pct": 23.7,
    "comparable_from": 2021,
    "spans_soc_revision": false
  },
  "pivots": [],
  "license": "https://cookedindex.com/terms"
}