Eran Kinsbruner at Checkmarx argues that AppSec must move beyond finding flaws to deciding which ones actually matter
AI is enabling application development at unprecedented speed. With large language models, developers are shifting from authoring code to editing it, with 49% of production code now being AI-generated.
That has its benefits. Microsoft Research, for example, found developers using GitHub Copilot were 55.8% faster on an identical task than developers without it. Yet this acceleration in productivity comes with a cost. Indeed, as the production of code grows and development cycles compress, the number of potential security issues entering software pipelines also rises.
This fundamentally changes what organisations need from application security. As software is spun up faster than ever before with AI, many organisations are struggling to keep up with the necessary checks and balances.
Visibility alone is no longer adequate. In the AI-driven software development era, organisations need the ability to generate and leverage actionable insights to understand risk in context, focus attention, and prioritise vulnerability remediation.
Of course, prioritising security in company codebases has been a challenge long before AI app development entered the mainstream, namely due to the fact that code can be written in a multitude of different languages. Indeed, there are more than 50 active coding languages currently being used.
AI, however, is now amplifying that problem, responding to prompts and requests by generating code in whatever language it deems to be most suitable for the task at hand.
This combination of more code being written more quickly in more coding languages means that apps are built faster than they can be evaluated and understood, increasing the potential for coding errors and security vulnerabilities to slip through the net.
While AI-generated code might bring productivity gains for developers, the security risks are heightened. Indeed, according to Checkmarx’s 2026 Future of Application Security survey, firms that are producing 81-100% of their code using AI ship known vulnerabilities at 3.4 times the rate of organisations that use AI for just 1-20% of code production.
Compounding this is the fact that threat actors are now leveraging AI to their own advantage, using it to actively seek out and exploit these vulnerabilities at speed. In June 2026, Anthropic showed that its large language model, Claude Mythos Preview, could weaponise N-day software patches into working code-execution exploits within an hour of a patch being issued, cutting exploit development time significantly.
As such, the number of vulnerabilities is rising and the time to exploit is shrinking. According to the Zero Day Clock dashboard, the proportion of exploitations occurring on or before the day of disclosure is more than 80%.
That’s a real concern. While defenders lean more heavily on AI-generated code that can be difficult to assess, exacerbating security vulnerabilities, attacks can now exploit those very same issues in the space of hours rather than weeks or months.
As a result, we are now at an inflection point in application security.
For years, the focus has been on improving the detection of vulnerabilities. However, with AI-generated code driving a significant uptick in the volume of code and vulnerabilities within it, security teams are now unable to investigate and remediate issues quickly enough.
Adding alerts to ever-growing SOC backlogs will only lead to fatigue if security teams lack the capacity or context to determine the greatest risks. Today, the focus needs to shift away from visibility and towards prioritisation.
The ability to distinguish between theoretical issues and genuine risk is becoming a core AppSec capability, yet it is important to acknowledge the strengths and weaknesses of existing means of doing so.
The foundation for scanning code is the approach of deterministic scanners, which rely on a base of known rules, signatures, and patterns to identify threats. It’s consistent and repeatable, which is why auditors and compliance teams trust it. Run it twice on the same code, and you’ll get the same result however, known vulnerabilities are only part of the picture. Often, the more difficult challenge is identifying risks with no known CVE or established pattern.
Here, an AI-based scanning system can help, with firms now able to leverage frontier AI models to hunt for zero-day and unknown-pattern findings that don’t yet have a CVE or signature. These models reason through code, much like a human reviewer, which increases the chance of catching unknown risks or threats. Yet the use of AI can also lead to inconsistencies in results.
Both approaches fall short in different ways. Deterministic models can’t identify novel vulnerabilities, while AI models lack certainty.
To close the gap and effectively identify and prioritise issues and vulnerabilities in code, AppSec teams need to take a hybrid approach that combines AI-driven analysis with contextual understanding and rigorous validation.
Detection is essential, but it is only the starting point. Moving forward, AppSec will rely on identifying the vulnerabilities which matter the most and focusing remediation efforts where the risks are greatest. That includes at the point of code creation through IDE’s or AI agents – enabling developers to implement “fixes” before they’re found or even created for that matter. In doing so, teams prevent a backlog of ‘vulnerability debt’ from stacking up.
Here, it’s important to get the scanning systems right. The foundations for deterministic models, for example, must be built on years of research in order to deliver consistent, high-precision vulnerability detection across established languages and attack patterns.
With those building blocks in place, app developers and security teams will be able to identify vulnerabilities and prioritise them with ease. The key is to ensure that results are precise enough to avoid the noise of false positives, while also being broad enough to surface complex or novel vulnerabilities that static rules alone would miss.
Eran Kinsbruner is Vice President of Product Marketing at Checkmarx
Main image courtesy of iStockPhoto.com and sankai
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
