70% of devs say AI code has more vulns; 30% ship it anyway — Checkmarx survey

Checkmarx's annual AppSec survey of 2,350 global developers, CISOs, and AppSec managers reveals a grim picture: 70% of respondents believe AI-generated code contains significantly more vulnerabilities, yet 30% knowingly ship vulnerable code into production. The 2026 survey follows similar reports since 2023, with a 54% larger sample this year.
Key findings
- AI-generated code share dropped slightly — from 54% to 49% of production code, but still high.
- 70% report significantly more vulnerabilities with AI-generated code vs human-written code.
- 30% knowingly ship vulnerable AI code into production, citing pressure to deploy quickly, difficulty fixing, or reliance on other controls.
- 93% of organizations suffered one or more security breaches from vulnerable applications (down from 98% last year).
- Open source accounts for 59% of production code, adding risk from malicious packages in npm, PyPI.
- Orgs where 81-100% of code is AI-generated ship vulnerable code at 3.4x the rate of those at 1-20% adoption.
Checkmarx researchers found that LLMs tend to underutilize modern language and compiler security features because training data contains outdated practices. A separate study from University of Central Florida and Birzeit University showed C code had the most AI-generated vulnerabilities, Python the fewest.
Quote from the report: "Risk is normalized." The authors caution that AI code volume correlates directly with vulnerable code deployment and breach frequency.
📖 Read the full source: HN AI Agents
👀 See Also

Claude Code's 'Honest Caveat' Tell Spikes: Data-Driven Analysis from r/ClaudeAI
A Reddit user tracked the rise of 'honest caveat' hedging in Claude Code outputs using Google search result counts as a proxy frequency measure.
Claude Code System Prompts v2.1.139: Claude Platform on AWS Docs, Summarization Security, PowerShell Tooling
CC 2.1.139 (+2,248 tokens) adds Claude Platform on AWS reference docs with SigV4 auth, security-preserving conversation summarization, PowerShell Unix command equivalence table, and several skill/prompt refinements.

IDP Leaderboard benchmark shows Claude Sonnet 4.6 matches Opus 4.6 for document AI tasks
The IDP Leaderboard tested 16 AI models on 9,000+ documents across OCR, table extraction, key extraction, visual QA, handwriting, and long documents. Claude Sonnet 4.6 scored 80.8 overall, essentially matching Opus 4.6 at 80.3, while Haiku 4.5 scored 69.6.

DeepSeek Withholds Latest AI Model from Nvidia and AMD
DeepSeek is withholding its latest AI model from U.S. chipmakers including Nvidia and AMD, according to Reuters sources. The article has 19 points and 3 comments on Hacker News.