Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 5IT NewsDeveloper

AI Writes Half Our Code Now. It Still Fails Security Tests 44% of the Time.

The Next Web, Tuesday, July 28th, 2026

Veracode tracked 100-plus models over a year. Security pass rates have not moved off 56%, even as AI took over half the codebase and every other capability climbed.

Veracode's 2026 GenAI Code Security Report tracked over 100 AI models and found that while they produce compilable code nearly 100% of the time, they fail security tests 44% of the time-a rate unchanged over a year despite AI now writing roughly half of all committed code.

The report dispels assumptions that specialized coding models, larger models, or scaling improve security outcomes. Only reasoning models showed marginal improvement at 56% versus 51% for others.

By language, Python passed 63% of tests while Java managed only 30%, and models perform poorly on cross-site scripting and log injection vulnerabilities despite handling SQL injection and cryptography reasonably well.

more →  ·  More from Developer →