Site navigation

83% of Organisations Use AI for Coding

Tom Quinn

,

ai coding risks
“New threats, such as AI poisoning and model escape, have started to emerge while massive waves of generative AI code are being used  by developers and novices in ways still to be  understood,” said Kevin Bocek, chief innovation officer at Venafi.

New research from Venafi, a machine identity management provider, has found that 83% of organisations are using AI for coding, and open source software is present in 61% of applications.

The study, based on a survey of 800 security decision makers (SDMs) across the USA, UK, France and Germany, also found that two-thirds (66%) of security leaders say it’s impossible for security teams to keep up with AI-powered developments.

While 72% of SDMs say they ‘have no choice’ in allowing the use of AI for coding to remain competitive, 63% have considered banning the practice due to security risks. 

The concerns over AI-generated code run deep, with 78% of SDMs worried that AI coding will lead to a security reckoning, and 59% losing sleep over the security implications. Two-thirds (63%) of SDMs went further, saying they thought it was impossible to govern the safe use of AI in their organisation, because they don’t have visibility into where AI is being used. 

Despite the growing worries, 57% of security leaders said it has become common practice to use AI to generate code, and less than half of companies (47%) have policies in place to ensure the safe use of AI within development environments.

The research also highlights that it is not only AI’s use of open source that could present challenges to security teams.

On average, security leaders estimate 61% of their applications use open source, which could present potential risks given that 86% of respondents believed open source code encourages speed rather than security best practice. 

Ninety percent of security leaders trust code in open source libraries, with 43% saying they have complete trust, but 75% said it is impossible to verify the security of every line of open source code. 


Recommended reading


One possible solution to these problems could be code signing, the process of digitally signing executables and scripts to confirm the software author, and guarantee that the code has not been altered or corrupted since it was signed. 

According to the research,  92% of security leaders believe that code signing should be used to ensure open source code can be trusted.

“Security teams are stuck between a rock and a hard place in a new world where AI writes code,” said Kevin Bocek, chief innovation officer at Venafi. “Anyone today with an LLM can write code, opening an entirely new front. Authenticating code, applications and workloads based on its identity to ensure that it has not changed and is approved for use is our best shot today and tomorrow.”

Tom Quinn

Staff Writer, DIGIT

Latest News

Cybersecurity Editor's Picks Recruitment Security

Comment | Building Cyber Talent Takes More Than a Degree

Culture Featured Technology

Inside TecTonic’s Growing Innovation Market Square

Cybersecurity

Revolut Leaked Customer Data to Fake Government Email Account

Cybersecurity Editor's Picks Security

Welsh SMEs Urged to Strengthen Cyber Defences