According to a new report, a wave of AI adoption is radically shifting how software goes from ideation to deployment.
Black Duck Software Inc’s new Global State of DevSecOps2024 report polled more than 1,000 IT professionals around the world in varied positions, delving into the impact new technologies have had on the development and security operations.
Nearly all survey respondents – over 90% – said that they are using AI in some capacity for their software development process, demonstrating just how crucial it is for organisations to take the proper security measures throughout the entire development lifecycle.
And yet, 67% of respondents were concerned about security AI-generated code.
Industries across the technology, cybersecurity, fintech, education, banking/financial, healthcare, media, insurance, transportation, and utilities sectors reported similar high adoption, underscoring the importance of having seamless security mechanisms in place.
In the non-profit sector, which is traditionally slower to adopt technological advancements due to constrained resources, at least half of organisations surveyed reported that they were using AI.
Unsurprisingly, the larger the organisation, the more likely it has significantly adopted some facet of AI in its software development.
“AI is a technology enabler that should be invested in, not feared, so long as the proper guardrails are being prioritised,” said Jason Schmitt, CEO of Black Duck.
“For DevSecOps teams, that means finding sensible uses to implement AI into the software development process and layering the proper governance strategy on top of it to protect the heart and soul of an organisation – its data.”
Recommended
- How Will the Met Tower Redevelopment Add to Glasgow’s Tech Sector?
- Report: Growing Urgency for Observability and Security to Converge
- Who Do British People Trust the Most and Least With Their Data?
- SBRC: Four-day Week Could Help Close Skills Gap
The Views on AI
A large majority (85%) of survey respondents noted that they have at least some measures in place to address the challenges posed by AI-generated code, such as potential IP, copyright, and license issues that an AI tool may introduce into proprietary software.
However, less than a quarter (24%) are ‘very confident’ in their policies and processes for testing this code.
Security Vs Speed
More than half of respondents (61%) said that security testing moderately or severely slows down development.
Half (50%) of those that feel this way also say that most projects are still being added manually.
Testing the Tools
A broad proliferation of tools may be leading to high levels of testing inconsistencies.
A whopping 82% of organisations are using between six and 20 different security testing tools, making it challenging to effectively integrate and correlate results across platforms and pipelines, leading to difficulty in distinguishing between genuine issues and false positives.





