Rapid AI-driven development makes security unattainable, warns Veracode
(2026/02/26)
- Reference: 1772119567
- News link: https://www.theregister.co.uk/2026/02/26/veracode_security_ai/
- Source link:
Veracode has posted its annual State of Software Security report, based on data from 1.6 million applications tested on its cloud platform, finding that more vulnerabilities are being created than are being fixed, and that high-velocity development with AI is making comprehensive security unattainable.
The company defines security debt as "known vulnerabilities left unresolved for more than a year" and reckons this now affects 82 percent of companies, up from 74 percent a year ago. High-risk vulnerabilities, meaning flaws that are both severe and likely to be exploited, have risen from 8.3 percent to 11.3 percent. The figures are from a combination of static analysis (analyzing the code), dynamic analysis (testing runtime behavior), software composition analysis (examining software components such as library dependencies), and manual penetration testing.
There is also some good news. The number of apps with open source vulnerabilities has reduced from 70 percent to 62 percent, and the overall "flaw prevalence" is down from 80 percent to 78 percent.
[1]
The researchers cite increasing use of testing tools as one of the factors behind the increase, suggesting that one factor in the worsening numbers is that more problems are being spotted that might previously have been missed. The number of false positives is unknown, so the figures may not be as bad as they first appear.
[2]
[3]
[4]According to Veracode , though, there is also an accelerating pace of software releases causing new code to be added more quickly than existing vulnerabilities are addressed. The researchers see growing technical complexity too, attributed to more AI-generated code, which makes remediation more difficult.
[5]
Application security is an increasing problem, according to Veracode's latest report
Nailing down the impact of AI is difficult, since the software security company also suggests that AI tools can help identify vulnerabilities and automate fixes. And the researchers note that malicious actors might succeed with AI penetration tools, or manipulate models via techniques such as prompt injection.
[6]Claude collaboration tools left the door wide open to remote code execution
[7]Cloudflare experiment ports most of Next.js API 'in one week' with AI
[8]Execs love AI, just not enough to pay for user training
[9]Bcachefs creator insists his custom LLM is female and 'fully conscious'
Veracode makes the usual nod to the importance of human oversight of AI tools, though exactly what that means is uncertain. In Cloudflare's [10]latest AI coding effort , for example, in which a significant application was built in a week with no human review of most of the code, it seems inevitable that security is either neglected or entrusted largely to AI despite its known flaws. AI tools are also good at generating false positives, creating a burden for human code reviewers that may be unmanageable.
"The velocity of development in the AI era makes comprehensive security unattainable," the report states, a bleak conclusion. Further, "the remediation gap has reached crisis proportions; incremental improvements insufficient; transformational change required."
Identifying what that change should be is elusive; one suspects that the industry will promote more AI tooling as the answer, despite evidence from reports like this one that it is currently failing to improve matters. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.veracode.com/blog/2026-state-of-software-security-report-risky-security-debt/
[5] https://regmedia.co.uk/2026/02/26/veracode-chart.jpg
[6] https://www.theregister.com/2026/02/26/clade_code_cves/
[7] https://www.theregister.com/2026/02/25/cloudflare_nextjs_api_ai/
[8] https://www.theregister.com/2026/02/25/few_firms_investing_in_the/
[9] https://www.theregister.com/2026/02/25/bcachefs_creator_ai/
[10] https://www.theregister.com/2026/02/25/cloudflare_nextjs_api_ai/
[11] https://whitepapers.theregister.com/
The company defines security debt as "known vulnerabilities left unresolved for more than a year" and reckons this now affects 82 percent of companies, up from 74 percent a year ago. High-risk vulnerabilities, meaning flaws that are both severe and likely to be exploited, have risen from 8.3 percent to 11.3 percent. The figures are from a combination of static analysis (analyzing the code), dynamic analysis (testing runtime behavior), software composition analysis (examining software components such as library dependencies), and manual penetration testing.
There is also some good news. The number of apps with open source vulnerabilities has reduced from 70 percent to 62 percent, and the overall "flaw prevalence" is down from 80 percent to 78 percent.
[1]
The researchers cite increasing use of testing tools as one of the factors behind the increase, suggesting that one factor in the worsening numbers is that more problems are being spotted that might previously have been missed. The number of false positives is unknown, so the figures may not be as bad as they first appear.
[2]
[3]
[4]According to Veracode , though, there is also an accelerating pace of software releases causing new code to be added more quickly than existing vulnerabilities are addressed. The researchers see growing technical complexity too, attributed to more AI-generated code, which makes remediation more difficult.
[5]
Application security is an increasing problem, according to Veracode's latest report
Nailing down the impact of AI is difficult, since the software security company also suggests that AI tools can help identify vulnerabilities and automate fixes. And the researchers note that malicious actors might succeed with AI penetration tools, or manipulate models via techniques such as prompt injection.
[6]Claude collaboration tools left the door wide open to remote code execution
[7]Cloudflare experiment ports most of Next.js API 'in one week' with AI
[8]Execs love AI, just not enough to pay for user training
[9]Bcachefs creator insists his custom LLM is female and 'fully conscious'
Veracode makes the usual nod to the importance of human oversight of AI tools, though exactly what that means is uncertain. In Cloudflare's [10]latest AI coding effort , for example, in which a significant application was built in a week with no human review of most of the code, it seems inevitable that security is either neglected or entrusted largely to AI despite its known flaws. AI tools are also good at generating false positives, creating a burden for human code reviewers that may be unmanageable.
"The velocity of development in the AI era makes comprehensive security unattainable," the report states, a bleak conclusion. Further, "the remediation gap has reached crisis proportions; incremental improvements insufficient; transformational change required."
Identifying what that change should be is elusive; one suspects that the industry will promote more AI tooling as the answer, despite evidence from reports like this one that it is currently failing to improve matters. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aaB8MwAQanmuuJtwtrJABAAAAYc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.veracode.com/blog/2026-state-of-software-security-report-risky-security-debt/
[5] https://regmedia.co.uk/2026/02/26/veracode-chart.jpg
[6] https://www.theregister.com/2026/02/26/clade_code_cves/
[7] https://www.theregister.com/2026/02/25/cloudflare_nextjs_api_ai/
[8] https://www.theregister.com/2026/02/25/few_firms_investing_in_the/
[9] https://www.theregister.com/2026/02/25/bcachefs_creator_ai/
[10] https://www.theregister.com/2026/02/25/cloudflare_nextjs_api_ai/
[11] https://whitepapers.theregister.com/
Re: Security is HARD
ecofeco
An acquaintance of mine was studying the latest course for full security certification about 6 months ago. I got to look over his shoulder a lot. It was... a nightmare.
So much shit piled as high as a mountain. There is no way the current system can do anything BUT fail.
I'll use my new knowledge for myself, but I would NEVER want to set myself up for failure by doing it as a job.
Doctor Syntax
Security Convenience is our first priority.
And checking thinks is so inconvenient.
Well
ecofeco
Duh?
Security is HARD
Which is why many developers are afraid of writing code that handles even the simplest of errors. I've found CompScience Grads who don't understand error handling let alone writing secure code.
Then we get AI slop muddying the waters. until someone teaches the LLM even the basic concepts of 1) defensive programming 2) error handling and compensation let alone 3) how to make the system secure, we are DOOMED to the old GIGO model.
AI is not the answer to life, the universe or ANYTHING even remotely USEFUL. Just my opinion.