AI writes half our code now. It still fails security tests 44% of the time.
What happened
AI now writes compilable code reliably, hitting almost a 100 percent success rate. But when it comes to security, the story is different. Veracode’s 2026 GenAI Code Security Report tested over 100 AI models at multiple points during the year. They found that nearly 44 percent of the code produced by these models still fails security tests. This failure rate has stayed roughly the same despite advances in AI coding capabilities.
Why it matters
Coders and companies adopting AI assistants for software development may be getting a false sense of security. Code that compiles does not mean code that is safe. Almost half the AI-generated code contains exploitable security flaws, exposing businesses to debugging costs, compliance hits, and breach risks. This persistent security gap puts pressure on DevOps teams to ramp up review and testing processes instead of blindly trusting AI outputs. It also signals that security improvements have not kept pace with AI’s rapid expansion into coding tasks.
What to watch next
Security-focused AI toolmakers, and providers of code scanning and testing services, have a clear opportunity to differentiate by closing this persistent quality gap. Watch for new integrations that combine AI coding with real-time vulnerability detection. Developers and security leads should track updates to AI models that improve secure coding practices or introduce security-aware training. Regulatory or procurement policies demanding security validation of AI-generated code could soon rise, adding compliance pressure to AI-powered development workflows.
AI Quick Briefs Editorial Desk