Veracode: AI now writes half of all code, but security pass rate stuck at 56%
WeldPond · x · 2026-10-11
Veracode's 2026 GenAI Code Security Report finds AI now writes roughly half of all committed code in adopting organizations, yet the average security pass rate across 100+ models tested since 2023 is stuck at 56%—syntax is nearly perfect, security is not. Even the top model fails nearly one in three security tasks.
A companion webinar (Oct 22) with Chris Wysopal and Jim Manico will cover intent-based coding—giving AI explicit, framework-specific security requirements before generation rather than after—and AI-SAST as a deterministic verification layer for release gates. The report's choice to test models without security-specific prompting is framed as the opening for this approach.
More from coding & agent
- NTU Study: Agent Harness Quality Depends on Model-Task Combo, No Universal Winner — jiqizhixin · 2026-10-11
- Agents are just a loop: the hard part isn't the framework, it's the evals — alex_verem · 2026-10-11
- In ~10 hours, Codex shipped a Cool Spot game remake while Claude hit 25% — ssh4net · 2026-10-11
- Local AI live coding: AMD Strix Halo + OpenCode with an MCP server for requirements — julianharris · 2026-10-11
- Maintainer: good AI PRs come from other maintainers, so we gate AI contributions — vboykis · 2026-10-11
- Dev plans 24/7 agents in VMs powering a cross-device personal AI assistant app — gnukeith · 2026-10-11