While AI code becomes increasingly mainstream, governance, lags, with rising security threats from shadow APIs, code sharing, and the unregulated use of AI assistants.
This is according to Checkmarx, an agentic AI-powered security firm, which surveyed more than 1,500 CISOs, AppSec managers and developers across North America, Europe, and Asia-Pacific to understand how organisations are adapting to a world where software is increasingly written by machines.
The findings paint a stark picture, with half of respondents already using AI security code assistance and 34% admitting that more than 60% of their code is AI-generated.
Yet, only 18% have policies governing this use, with the growing adoption of AI coding assistants is eroding developer ownership and expanding the attack surface.
The research also shows that business pressure is normalising risky practices. Eighty-one per cent of organisations knowingly ship vulnerable code, and 98% experienced a breach stemming from vulnerable code in the past year – a rise from 91% in 2024.
Within the next 12 to 18 months, nearly a third (32%) of respondents expect API breaches via shadow APIs or business logic attacks.
Despite these realities, fewer than half of the respondents report deploying foundational security tools, such as using mature application security tools such as dynamic application security testing (DAST) or infrastructure‑as‑code scanning.
While DevSecOps is widely discussed industry-wide, only half of organisations surveyed actively use core tools and just 51% of North American organizations report adopting DevSecOps.
“The velocity of AI‑assisted development means security can no longer be a bolt‑on practice. It has to be embedded from code to cloud,” said Eran Kinsbruner, vice president of portfolio marketing.
“Our research shows that developers are already letting AI write much of their code, yet most organisations lack governance around these tools. Combine that with the fact that 81% knowingly ship vulnerable code and you have a perfect storm. It’s only a matter of time before a crisis is at hand.”
Recommended reading
- AI Risks and Talent Gaps Challenge CFOs in 2024
- ‘Shadow AI’ Use Is Threatening Enterprise Data Security
- Cyber Leaders Reveal Compliance and Boardroom Struggles
The report outlines six strategic imperatives for closing the application security readiness gap: move from awareness to action, embed “code‑to‑cloud” security, govern AI use in development, operationalise security tools, prepare for agentic AI in AppSec, and cultivate a culture of developer empowerment.
Kinsbruner added, “To stay ahead, organisations must operationalise security tooling that is focused on prevention. They need to establish policies for AI usage and invest in agentic AI that can automatically analyse and fix issues real-time. AI generated code will continue to proliferate; secure software will be the competitive differentiator in the coming years.”
Chris Ledingham, Director Northern Europe, comments: “Our research found that nearly one third, 32%, of European respondents say their organisation often deploys code with known vulnerabilities, compared with 24% of those in North America. This suggests the need for a stronger focus across our region on embedding security into development.
With AI now writing much of the code base, security leaders face heightened accountability. Boards and regulators will rightly expect CISOs to implement robust governance for AI generated code and to ensure vulnerable software isn’t being pushed to production.”





