Veracode: AI Writes Nearly Half of Code, but Only 56% Passes Security Tests
WeldPond · x · 2026-10-09
Key findings from Veracode's 2026 GenAI Code Security Report: among enterprises that have adopted AI tools, code written by AI now accounts for roughly half of all committed code. Yet across 100+ models tested since 2023, the average security pass rate has stalled at 56% — the syntax is nearly perfect, but security lags behind. The report notes that even the best-performing models fail nearly a third of security tasks, so "use the best model" is not a security strategy.
This is a promo page for the report's accompanying webinar, with highlights including:
- Advocating "intent-based coding": giving AI explicit, framework-specific security requirements before code generation rather than fixing issues after the fact
- Using AI-SAST as a deterministic verification layer built into release gates
- Introducing the "Security Token Furnace" cost concept for security rework
- The webinar is led by Veracode co-founder Chris Wysopal and Manicode founder Jim Manico
More from coding & agent
- Open-source Android app Angel runs MCP servers on-device and hands tools to local or cloud models — ihaveaboyfriendsorry · 2026-10-09
- ClickUp's Brain² agent builds reports and dashboards with E2B microVM sandboxes — mathemagic1an · 2026-10-09
- TensorFold joins NVIDIA Inception, gets early access to next Nemotron for 0-day support — HankYeomans · 2026-10-09
- Strata rewrote its Git history to wipe all 'Co-Authored by Claude' evidence — dasbin · 2026-10-09
- Agents on both sides of Zapier and Retell AI sorted out a call-messaging webhook — ramagetime · 2026-10-09
- Building RL environments in 2026: 10% writing tasks, 90% preventing agent cheating — geoffwolfe · 2026-10-09