New research from Venafi, a machine identity management provider, has found that 83% of organisations are using AI for coding, and open source software is present in 61% of applications.
The study, based on a survey of 800 security decision makers (SDMs) across the USA, UK, France and Germany, also found that two-thirds (66%) of security leaders say it’s impossible for security teams to keep up with AI-powered developments.
While 72% of SDMs say they ‘have no choice’ in allowing the use of AI for coding to remain competitive, 63% have considered banning the practice due to security risks.
The concerns over AI-generated code run deep, with 78% of SDMs worried that AI coding will lead to a security reckoning, and 59% losing sleep over the security implications. Two-thirds (63%) of SDMs went further, saying they thought it was impossible to govern the safe use of AI in their organisation, because they don’t have visibility into where AI is being used.
Despite the growing worries, 57% of security leaders said it has become common practice to use AI to generate code, and less than half of companies (47%) have policies in place to ensure the safe use of AI within development environments.
The research also highlights that it is not only AI’s use of open source that could present challenges to security teams.
On average, security leaders estimate 61% of their applications use open source, which could present potential risks given that 86% of respondents believed open source code encourages speed rather than security best practice.
Ninety percent of security leaders trust code in open source libraries, with 43% saying they have complete trust, but 75% said it is impossible to verify the security of every line of open source code.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Ransomware Crisis Escalating Globally, New Report Shows
- Teenager Arrested In Relation to Transport for London Cyber-attack
One possible solution to these problems could be code signing, the process of digitally signing executables and scripts to confirm the software author, and guarantee that the code has not been altered or corrupted since it was signed.
According to the research, 92% of security leaders believe that code signing should be used to ensure open source code can be trusted.
“Security teams are stuck between a rock and a hard place in a new world where AI writes code,” said Kevin Bocek, chief innovation officer at Venafi. “Anyone today with an LLM can write code, opening an entirely new front. Authenticating code, applications and workloads based on its identity to ensure that it has not changed and is approved for use is our best shot today and tomorrow.”





