Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-generated code and AppSec debt: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: As AI-generated code enters production workflows, 81% of organisations knowingly ship vulnerable code and 45% of AI-generated code may be insecure, according to Checkmarx research cited alongside Gartner guidance. The governance gap is now larger than the tooling gap, because speed without accountable review and continuous enforcement converts productivity into security debt.

NHIMG editorial — based on content published by Checkmarx: AI coding paradox and AppSec infrastructure gaps

By the numbers:

Questions worth separating out

Q: How should security teams govern AI-generated code in production pipelines?

A: Security teams should treat AI-generated code as a controlled identity event, not just a development artifact.

Q: Why do AI-assisted coding tools complicate security assurance for enterprise software?

A: They increase code output faster than teams can prove the output is safe.

Q: What do teams get wrong about scanning AI-generated code at the end of a sprint?

A: Teams often assume one strong scan can compensate for rapid code generation, but that model is too late for modern workflows.

Practitioner guidance

  • Assign an accountable AI software lead Name a specific owner for the security and quality of AI-generated code, with authority to block release when accepted risk exceeds policy.
  • Build policy gates for AI tool usage Create allow and deny lists for coding assistants, model endpoints, and MCP servers used in development.
  • Move AppSec checks into the developer workflow Run security validation in the IDE and pull request stage, not only at sprint end.

What's in the full article

Checkmarx's full article covers the operational detail this post intentionally leaves for the source:

  • Gartner's specific guidance on AI software leads and how responsibility should be assigned in engineering teams.
  • The Checkmarx One workflow details for combining ASPM, centralized AI-BOM visibility, and enforcement across the AI toolchain.
  • Examples of developer assist, triage assist, and remediation assist in the pull request and IDE workflow.
  • The layered detection approach that blends deterministic and AI-driven analysis to reduce false positives.

👉 Read Checkmarx's analysis of AI-generated code risk and AppSec governance →

AI-generated code and AppSec debt: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-generated code creates governance debt, not just code debt. The article shows that the main failure is not output quality alone but the absence of accountable control over how AI-generated code is accepted into the software lifecycle. When code is produced faster than teams can review it, governance becomes the limiting factor, not developer productivity. For application security teams, the practical conclusion is that AI output must be treated as governed production material, not disposable draft code.

A question worth separating out:

Q: How can organisations tell whether AI governance is actually working?

A: Organisations can tell AI governance is working when they can inventory every agent, explain its purpose, show who owns it, and prove that permissions are tightly scoped. If those four things are missing, the programme has policy language but not operational control. Auditors will notice the gap quickly.

👉 Read our full editorial: AI-generated code is widening the application security gap



   
ReplyQuote
Share: