By NHI Mgmt Group Editorial TeamBased on Cerbos: “The productivity paradox of AI coding assistants” (September 12, 2025)

TL;DR: AI coding assistants can speed up scaffolding and boilerplate, but multiple studies cited by Cerbos show that experienced developers often slow down, review burden rises, and insecure output can increase privilege paths and secrets exposure. The real issue is not typing speed but whether production-ready code, credentials, and review gates can keep up.


At a glance

What this is: Cerbos argues that AI coding assistants create a productivity illusion in which faster drafting can mask slower delivery, more review work, and weaker production safety.

Why it matters: IAM and security teams need to treat AI-assisted development as an access and governance problem, because unsafe code generation can expand privilege paths, expose secrets, and bypass review controls.

By the numbers:

  • AI-generated code introduced 322% more privilege escalation paths and 153% more design flaws than human-written code, according to Apiiro research cited by Cerbos.

Context

AI coding assistants are not just a developer productivity issue. They are a governance problem because they change how quickly code, secrets, and privileged workflows move from prompt to production, and that changes the control assumptions teams rely on.

The article’s central claim is that AI can speed up MVP-style work, but it does not remove the bottlenecks that matter in production: review, testing, cleanup, and access control. Once those bottlenecks dominate, the security cost of AI-generated output becomes more visible than the typing speed gain.


Key questions

Q: How should security teams govern AI coding assistants that can execute commands?

A: Treat them as delegated non-human identities with bounded execution authority. Require human approval for destructive commands, keep command scopes narrow, and log every tool action. The key control question is not whether the assistant is helpful, but whether it can be prevented from acting outside intended scope when prompts, context, or rules are manipulated.

Q: Why do AI coding assistants create security debt even when code compiles?

A: Because compilation only proves syntax, not safety. AI models can produce code that works functionally while still introducing injection flaws, unsafe error handling, weak authentication, or risky dependencies. Security debt grows when teams accept that output without verification, since every unchecked suggestion can become a future remediation item.

Q: What breaks when AI-generated changes are reviewed only at merge time?

A: Merge-time review fails because AI-driven pipelines can create code, dependencies, workflows, and infrastructure in one step. By the time a human sees the change, the underlying security decisions may already be embedded across multiple artefacts. Teams need controls at generation, build, and runtime, not only at approval.

Q: Should organisations compare AI coding assistants with human-only development for sensitive systems?

A: Yes, but the comparison should focus on change quality, review burden, and secret exposure rather than raw output speed. For sensitive systems, the safer choice is the one that preserves clear approval gates and keeps credential handling inside governed workflows.


Technical breakdown

Why AI-assisted code often feels faster than it ships

AI coding tools create an immediate reward loop: a prompt produces code, which feels like progress even when the result still needs review, repair, or replacement. That perception gap matters because delivery work is constrained less by typing and more by architecture, test coverage, code review, and release coordination. In practice, assistants can shorten the drafting phase while lengthening the verification phase. The larger the context and the more complex the codebase, the more likely the output becomes partially correct rather than production-ready. Practical implication: measure end-to-end delivery time, not prompt-to-output speed.

Practical implication: Measure end-to-end delivery time, not prompt-to-output speed.

How AI coding assistants expand secrets and privilege risk

AI-generated scaffolding can introduce hard-coded credentials, API keys, and permission patterns that developers might not have written by hand. The risk is not only that a secret appears in code, but that it can be copied into prompts, logs, or external processing paths outside the organisation’s control. Privilege escalation paths also increase when generated code connects components more broadly than a human reviewer intended. That turns AI-assisted coding into an identity and access problem, not just an application-security problem. Practical implication: treat assistant-generated code as a source of new entitlement pathways and secret exposure points.

Practical implication: Treat assistant-generated code as a source of new entitlement pathways and secret exposure points.

Why the last 30% of production readiness is where AI breaks down

The article’s 70% problem is really a boundary problem. AI tools can scaffold a feature quickly, but the final 30% includes edge cases, tests, secure configuration, and integration details that determine whether software is safe to ship. That final stage is where context rot, inconsistent patterns, and overconfident review can create technical debt at speed. For identity teams, this means the governance question is not whether AI can draft code, but whether the organisation can prove that AI output still satisfies production controls before release. Practical implication: shift approval gates toward production-readiness checks, not draft completion.

Practical implication: Shift approval gates toward production-readiness checks, not draft completion.


  • Nx s1ngularity attack 2025: Attackers stole Nx's npm token via a GitHub Actions flaw and shipped malware that stole 2,349 secrets and abused developers' AI CLIs.
  • Sentry MCP Agentjacking 2026: Researchers showed a fake Sentry error, posted with a public DSN, could make AI coding agents run attacker code with developers' credentials.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Productivity is the wrong unit of control when AI coding assistants are in the delivery chain. Cerbos’ evidence shows that apparent speed can coexist with slower senior developers, more review work, and worse security outcomes. That means the governance problem is not tool adoption, but whether organisations are measuring the right end point: production-ready change, not prompt throughput.

AI-generated code creates an identity and privilege expansion problem, not just a code-quality problem. When assistants scaffold access paths, embedded credentials, or broad service connections, they can widen the effective blast radius of a change set. The relevant concept here is identity blast radius: the amount of access, trust, and downstream reach a generated change can introduce before anyone notices. Practitioners should treat generated code as a privilege-bearing artifact.

Access review assumptions break when code is created faster than it can be governed. Review processes assume humans can inspect, understand, and validate changes before they reach production. AI-assisted commits compress that window and can make insecure patterns normal before reviewers detect them. The implication is that engineering and IAM controls need to move closer to issuance and merge time, because post-hoc scrutiny is too late.

Secrets management fails when developers can paste credentials into a conversation as easily as into a repository. The article makes clear that one of the highest risks is accidental disclosure of API keys, tokens, or configuration data into assistant workflows. That is not just leakage, it is a governance failure over where credentials are allowed to exist. Teams should treat AI assistants as part of the secret handling boundary, not outside it.

Human judgement remains the decisive control even when AI accelerates the first draft. The strongest practical pattern in the article is not rejection of AI, but disciplined use in low-risk, repetitive work where the output is easy to verify. For anything that touches production access, privilege, or release gating, the control value still comes from experienced review and explicit boundaries. Practitioners should keep AI in the drafting lane and keep governance in the shipping lane.

From our research library:

What this signals

Identity blast radius: AI-assisted code can widen the access and trust surface of a change long before it is obvious in review. That means teams need to evaluate generated code as a privilege-bearing artifact, not only as a software artifact.

The control point is shifting toward merge-time governance. When assistants can introduce secrets, privilege paths, and configuration drift faster than teams can inspect them, the real question becomes whether release controls can stop unsafe patterns before they become normal.

According to the State of Secrets Sprawl 2026, Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025.


For practitioners

  • Define approved AI coding use cases Limit assistant use to MVPs, experiments, boilerplate, and low-risk scaffolding where review burden is manageable and failures are easy to detect. Keep production changes, access logic, and credential handling under stricter human review.
  • Scan for secret exposure in prompts and output Treat pasted API keys, tokens, and config snippets as potential disclosure events. Monitor logs, chats, and generated files for secrets, then revoke and rotate any credentials that may have left the environment.
  • Tighten merge gates on assistant-generated code Require security review for changes that add privilege paths, authentication logic, or external integrations. Make review criteria explicit so generated code is judged on production readiness, not just compilation success.
  • Measure delivery outcomes, not perceived speed Track rework, reviewer comment volume, defect escape rates, and time to production for AI-assisted work. Use those signals to decide where AI helps and where it creates hidden delay.

Key takeaways

  • AI coding assistants can make drafting feel faster while increasing the amount of review, cleanup, and governance work needed before release.
  • The article ties assistant use to higher privilege-path creation, more secrets exposure, and heavier security review burden in production code.
  • The practical response is to constrain assistant use, strengthen merge gates, and measure real delivery outcomes instead of perceived velocity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02 — Secret LeakageThe article highlights pasted and generated secrets as a primary risk in AI-assisted coding.
NHI-05 — Overprivileged NHIGenerated code can introduce broader access paths than reviewers intended.
NHI-10 — Human Use of NHIDevelopers are using assistants as part of the identity and access workflow, which changes governance boundaries.
Recommendation — Scan assistant workflows for secret leakage and revoke any exposed credentials immediately. Review AI-generated access logic for privilege scope before it reaches production. Define where human-driven use of AI tooling is permitted in credential and release workflows.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article’s secret exposure risk maps to control over credential lifecycle and handling.
Recommendation — Apply authenticator management controls to rotate any credentials exposed in AI-assisted work.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on how generated code can widen access paths and entitlements.
Recommendation — Verify that AI-generated changes do not create unreviewed permissions or new authorisation paths.

Key terms

  • AI coding assistant: An AI coding assistant is software that helps write, refactor, debug, or navigate code using model-driven suggestions and sometimes command execution. In practice, it can become part of the operational control plane if it has access to files, terminals, and external tools that can change a system.
  • Privilege Escalation: An attack technique where a compromised identity, often an NHI with initially limited permissions, exploits vulnerabilities or misconfigurations to gain elevated access rights, typically leading to broader compromise.
  • Secrets Exposure: Secrets exposure is the accidental or uncontrolled disclosure of credentials such as API keys, tokens, certificates, and service passwords. In NHI programs, it matters because a leaked secret often behaves like a live identity, creating immediate access risk until it is revoked or rotated.
  • Production Readiness Gate: A production readiness gate is the set of checks a programme must pass before a pilot can become a live service. In AI environments, it includes identity controls, governance approval, observability, and support ownership, so the system can operate safely beyond the lab.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org