TL;DR: Black Hat USA 2025 highlighted how AI, software supply chain risk, and cloud security are converging into a tougher governance problem, while Veracode’s GenAI Code Security Report found nearly half of AI-generated code samples failed security tests and 83% of organisations are using AI for software development. The practical lesson is that AI adoption is outpacing security assurance, so controls must shift from review at the end to governance across the pipeline.
NHIMG editorial — based on content published by Veracode: Securing the Digital Frontier, key themes from Black Hat USA 2025
By the numbers:
- 83% of organizations are using AI for software development.
- With 61% of apps containing open-source dependencies, the software supply chain remains deeply exposed.
Questions worth separating out
Q: What breaks when AI-generated code is reviewed without security gates?
A: What breaks is the assumption that a clean-looking diff is a safe diff.
Q: Why do software supply chains create identity governance risk?
A: Because the identities that sign, build, approve, and deploy software can change the final outcome more than the code itself.
Q: What do security teams get wrong about SaaS posture management?
A: They often treat SSPM as a scanning problem instead of a governance problem.
Practitioner guidance
- Harden AI code review gates Require security scanning, secret detection, and policy checks on all AI-generated code before merge.
- Inventory pipeline identities and secrets Map every CI/CD token, service account, and API key that can change build or deployment state.
- Verify software provenance end to end Use signed artefacts, dependency locking, and package source verification to reduce the chance that a trusted build ingests malicious or tampered components.
What's in the full article
Veracode's full article covers the conference themes and product context this post intentionally leaves for the source:
- Veracode’s conference recap of AI, supply chain, and cloud sessions across Black Hat USA 2025.
- Discussion of the GenAI Code Security Report and the broader findings behind the nearly half failed security tests result.
- Context on the ASPM enhancements and integrations referenced in the article, including how the vendor positions them operationally.
- The specific threat-research example involving malicious packages and developer-machine compromise that was only briefly referenced here.
👉 Read Veracode’s Black Hat 2025 analysis of AI, supply chain, and cloud security →
Black Hat 2025 themes: what security teams need to prioritise now?
Explore further
AI security has moved from model risk to pipeline risk. The Black Hat themes show that organisations can no longer treat AI as a discrete governance issue. When AI writes code, recommends remediation, or assists in pipeline decisions, security assurance must cover the entire software lifecycle, including identity, access, and secrets that govern build systems. The practical conclusion is that AI security and application security are now operationally inseparable.
A question worth separating out:
Q: How should teams respond when AI, code, and cloud controls are managed separately?
A: They should build one operating model that links application security, cloud posture, and identity governance. That means shared ownership for secrets, deployment identities, and remediation workflows, plus a common prioritisation layer so teams can decide whether the real issue is code, configuration, or access.
👉 Read our full editorial: Black Hat 2025 exposed a widening AI, supply chain, and cloud risk gap