{"id":8433,"date":"2026-06-10T03:05:47","date_gmt":"2026-06-10T03:05:47","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8433"},"modified":"2026-06-10T03:05:47","modified_gmt":"2026-06-10T03:05:47","slug":"enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8433","title":{"rendered":"Enterprises know AI-generated code is vulnerable; they\u2019re shipping it anyway"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p>AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they\u2019re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away.<\/p>\n<p>It\u2019s a dangerous game to play at the dawn of the agentic AI era, as underscored in a <a href=\"https:\/\/checkmarx.com\/blog\/just-launched-the-future-of-application-security-in-the-era-of-ai-2027-industry-outlook\/\" target=\"_blank\" rel=\"noopener\">new report<\/a> from app security company Checkmarx.<\/p>\n<p>The survey of thousands of <a href=\"https:\/\/www.csoonline.com\/article\/4181920\/15-tough-cybersecurity-questions-every-ciso-must-answer.html\" target=\"_blank\" rel=\"noopener\">security leaders<\/a> exposes an underlying naivete about AI-built code and its vulnerabilities, even as tools like Anthropic\u2019s Mythos are uncovering security flaws orders of magnitude faster than any human security team could ever hope to.<\/p>\n<p>\u201cMythos-class models collapse the window between a vulnerability existing and a working exploit being available from months to minutes,\u201d the report notes. Enterprises relying on traditional security tools and methods, it says, \u201ccannot survive this reality.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Security as an afterthought<\/h2>\n<p>Checkmarx\u2019s survey of 2,350 CISOs, AppSec managers, and developers across 14 countries focused on how much AI-developed code enterprises are deploying, the vulnerabilities it introduces, how it impacts developer workflows, and overall sentiment about AI code and security posture.<\/p>\n<p>Today, nearly half of production code is AI-generated, and the majority of enterprises also report that at least half their codebase is made up of open-source components, according to the report.<\/p>\n<p>But the more AI-generated code that is pushed out, the more vulnerabilities are exposed. Enterprises who said 81% \u2013 100% of their code is built by AI ship vulnerable code 3.4 times more often than businesses using AI more conservatively, relying on 20% or less AI code.<\/p>\n<p>Additionally, 70% of developers said that AI code generation created vulnerabilities in 2025, and almost all enterprises surveyed (93%) had at least one security breach as a direct result of in-house developed apps.<\/p>\n<p>Still, risk is becoming \u201cnormalized,\u201d the report notes, with three-quarters of enterprises knowingly deploying vulnerable code as they face increased pressure for ROI. Startlingly, about 30% of respondents admitted they ship compromised code and hope the vulnerability won\u2019t be found. Similarly, more than a third of organizations leave half of their known vulnerabilities unfixed for 90 days or more.<\/p>\n<p>The report points out that the organizational bottleneck isn\u2019t detection, \u201cit\u2019s the human decision to ship anyway, suppress the finding, or defer to the next sprint.\u201d<\/p>\n<p>Along with this, AppSec teams are often limited to reactive incident response as they deal with tool sprawl. And developers only continuously secure code a small percentage of the time (18%), even though nearly all are equipped with security tooling.<\/p>\n<p>Ultimately, developers are \u201cset up to fail,\u201d the report contends. They face significant pressure to deliver, and are forced to choose quantity and speed over security. Yet, even as they face significant consequences when it comes to post-mortems, performance reviews, escalation, and blocked releases, the tools that contribute to security issues, delivering low-value findings, unclear guidance, or late feedback, continue to go unfixed.<\/p>\n<p>\u201cDevelopers remain accountable for outcomes, even when systems and workflows are not aligned to support them,\u201d the report notes.<\/p>\n<h2 class=\"wp-block-heading\">Overconfidence, outdated practices<\/h2>\n<p>Alarmingly, many enterprises seem to be deluded when it comes to their security posture. Of those that rate themselves as \u201chighly mature\u201d AI organizations, 42% often ship the most vulnerable code, and have breach rates \u201cbarely distinguishable\u201d from other enterprises.<\/p>\n<p>\u201cConfidence isn\u2019t protecting them,\u201d the report notes. \u201cIt\u2019s blinding them.\u201d<\/p>\n<p>Underscoring this, only 22% of organizations have formal AI governance, and developers still rely on manual code reviews to ensure their code meets compliance standards.<\/p>\n<p>The result is a mismatch between the speed of software creation and the speed of governance, the report notes. \u201cCompliance frameworks are evolving, but many organizations are still attempting to govern AI-scale development with processes designed for a slower era of software delivery.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Strategic imperatives for enterprises<\/h2>\n<p>Enterprises do seem to have wised up (a bit) after <a href=\"https:\/\/www.csoonline.com\/article\/4158117\/anthropics-mythos-signals-a-structural-cybersecurity-shift.html\" target=\"_blank\" rel=\"noopener\">Anthropic\u2019s Mythos<\/a> proved capable of not only discovering vulnerabilities across major operating systems and browsers, but exploiting them 100 times faster than previous Claude models. And the subsequent <a href=\"https:\/\/www.cio.com\/article\/4177294\/this-is-not-a-security-problem-anthropics-mythos-glasswing-and-how-the-industry-must-move-forward.html\" target=\"_blank\" rel=\"noopener\">Project Glasswing<\/a> almost immediately surfaced thousands of previously-unidentified security flaws.<\/p>\n<p>Checkmarx\u2019s survey, which, it should be noted, was conducted a month prior to Mythos\u2019 arrival, found that enterprises are finally taking proactive measures, focusing more heavily on AI security threats overall, and investing more in DevSecOps practices, automation, and developer training.<\/p>\n<p>The report emphasizes the importance of prioritizing risk over code volume; vulnerabilities should not be considered isolated incidents. Also, it\u2019s critical to <a href=\"https:\/\/csrc.nist.gov\/csrc\/media\/presentations\/2026\/secure-by-design\/2.4-secure_by_design-dukes-lee.pdf\" target=\"_blank\" rel=\"noopener\">embed security<\/a> into developer workflows rather than treating it as a checkpoint. Enterprises must have systems that reduce noise, provide clear guidance, and allow them to take action when an issue arises.<\/p>\n<p>Security \u201cmust be integrated directly into how developers write, test, and ship code within the IDE, pipelines, and AI-assisted workflows where development now happens,\u201d the report notes.<\/p>\n<p>Similarly, enterprises would benefit by reducing fragmentation and tool sprawl and defining ownership of the AI tools. By simplifying security stacks, they can align responsibilities and ensure consistent tool use, according to the report.<\/p>\n<p>Further, AI needs strong governance, and teams must move beyond outdated manual triage and \u201chuman-gated remediation.\u201d AI can fight AI in a strong system built to prioritize, remediate, and resolve risk \u201cwithout waiting for a human to approve each step,\u201d the report notes.<\/p>\n<p>Ultimately, it says: \u201cProgress depends on embedding intelligence directly into workflows, enabling risks to be prioritized, remediated, and resolved, all within the systems that they operate in.\u201d<\/p>\n<p><em>This article originally appeared on <a href=\"https:\/\/www.cio.com\/article\/4183209\/enterprises-know-ai-generated-code-is-vulnerable-theyre-shipping-it-anyway.html\" target=\"_blank\" rel=\"noopener\">CIO.com<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>AI-generated code is riddled with security flaws, yet enterprises are shipping more of it than ever before. Why? Perhaps they\u2019re over-confident, lack true visibility into security risks, or are simply choosing to ignore the problem and hope it goes away. It\u2019s a dangerous game to play at the dawn of the agentic AI era, as [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8434,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8433"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8433"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8434"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}