Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-generated code and AppSec governance: what teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: 81% of organisations knowingly ship vulnerable code, 54% of code is AI-generated, and 98% experienced a breach in the past year, according to Checkmarx’s panel and 2026 outlook report, underscoring how speed, shadow AI, and weak measurement are reshaping application security. The real issue is governance: security programmes now have to prove what is actually shipping, not just count findings.

NHIMG editorial — based on content published by Checkmarx: AppSec in the Era of Agentic AI

By the numbers:

Questions worth separating out

Q: How should security teams govern AI-generated code in production pipelines?

A: Security teams should treat AI-generated code as a controlled identity event, not just a development artifact.

Q: Why do AI code assistants create new secret exposure risk for IAM teams?

A: Because they sit close to source code, environment files, local shells, and developer credentials.

Q: What do security teams get wrong about measuring application risk maturity?

A: They often confuse output with progress.

Practitioner guidance

  • Establish approved AI-use policies for development Define which coding assistants, prompts, and generated outputs are permitted, then require logging and review for anything that touches production code or deployment logic.
  • Bind release gates to provenance and validation Require evidence showing where code came from, what automated checks ran, and who accepted residual risk before merge or deployment.
  • Measure remediation by exposure, not volume Track which vulnerabilities affect internet-facing systems, authentication paths, or high-value data, then measure time to verified remediation.

What's in the full article

Checkmarx's full article covers the operational detail this post intentionally leaves for the source:

  • The panel’s full quotes on why developers normalise vulnerable code and how that affects remediation behaviour.
  • The report-backed breakdown of how often organisations knowingly ship vulnerable code and how AI changes that pattern.
  • The discussion of budget framing, tool underuse, and why security leaders struggle to justify AppSec investment to the business.
  • The panel’s forward view on how agentic AI may change testing, remediation, and code validation workflows.

👉 Read Checkmarx’s panel discussion and 2026 AppSec outlook on AI-generated code risk →

AI-generated code and AppSec governance: what teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-generated code creates governance debt, not just development efficiency. When organisations cannot prove what was generated, reviewed, and approved, they inherit risk that is harder to assign, measure, and remediate. The problem is not the use of AI itself, but the lack of accountable controls around its output. For practitioners, the priority is to govern provenance before scale makes the gap invisible.

A question worth separating out:

Q: How can organisations reduce shadow AI risk without slowing adoption?

A: Organisations should reduce shadow AI risk by discovering unsanctioned tools first, then creating a clear approval path for approved services. Security teams need logging, rate limits, and policy enforcement on AI usage so users can adopt tools safely. The objective is visible governance, not blanket prohibition.

👉 Read our full editorial: AI-driven AppSec is exposing a governance gap in secure code delivery



   
ReplyQuote
Share: