TL;DR: A global survey of 2,350 CISOs, AppSec managers and developers across 14 countries found that 49% of production code is now AI-generated, 81% of organisations were breached twice or more in the past year, and only 9% fix more than 90% of vulnerabilities within 90 days, according to Checkmarx. The result is an AppSec model where detection is plentiful but risk still survives the decision chain.
NHIMG editorial — based on content published by Checkmarx: The Future of Application Security in the Era of AI
By the numbers:
- 49% of production code is now AI-generated.
- 81% of organizations were breached twice or more in the past 12 months.
- Only 9% of organizations fix more than 90% of vulnerabilities within 90 days.
Questions worth separating out
Q: What breaks when vulnerability findings are not verified after remediation?
A: Without verification, teams assume risk is gone when it may still be present.
Q: Why do AI-generated code changes increase application security risk?
A: AI-generated code can increase risk because it accelerates output faster than review, testing, and secret hygiene can keep up.
Q: How do you know if AppSec remediation is actually working?
A: Look for shrinking time-to-fix, fewer deferred exceptions and fewer vulnerabilities surviving multiple release cycles.
Practitioner guidance
- Measure remediation latency by control owner Track the time from vulnerability discovery to fixed deployment by application owner, not just by severity.
- Introduce code provenance checks for AI-generated work Require teams to identify where AI-generated code enters the pipeline and to apply stricter review or approval thresholds to those paths.
- Convert checkpoint review into continuous enforcement Move from periodic security gates to inline controls that fail builds, block release paths or trigger mandatory remediation when policy conditions are not met.
What's in the full report
Checkmarx's full report covers the operational detail this post intentionally leaves for the source:
- Regional breakdowns across 14 countries, including how breach rates and remediation differ by geography.
- Complete cross-tabulation of AI code volume against vulnerable code deployment and breach frequency.
- The three-way perception gap between CISOs, AppSec managers and developers, with role-by-role survey splits.
- Six strategic imperatives for closing the gap between detection and action, including the case for agentic security.
👉 Read Checkmarx's report on AI-generated code, AppSec risk and remediation delay →
AI-generated code and remediation delays: what should AppSec teams do?
Explore further
Detection without remediation is governance debt: this research shows that visibility has outpaced organisational decision-making. Security teams now know more, but they do not act faster, which means risk is accumulating in the review queue rather than disappearing from the environment. The real problem is not missing data, it is the inability to convert findings into enforced outcomes. Practitioners should treat this as a governance failure with direct control implications.
A question worth separating out:
Q: Should organisations treat developer friction as a security risk signal?
A: Yes. When developers spend large amounts of time on security but still ship vulnerable code, friction is telling you that the process is misaligned. That usually means the feedback is too late, the guidance is too vague or the approval chain is too slow to support secure delivery at scale.
👉 Read our full editorial: AI-generated code and slow remediation are widening AppSec risk