news.blackduck.com AI Governance Gap Poses Risks for Software Development
Article Content
- •97% of enterprise software engineers use AI coding assistants, but only 30% have governance.
- •Nearly 90% of teams face issues with AI-generated code, leading to bottlenecks and security risks.
- •Governance is essential for improving efficiency and mitigating operational risks in AI development.
A recent survey by Black Duck reveals that while 97% of enterprise software engineers are using AI coding assistants, only 30% have full governance in place. This gap is leading to significant operational challenges, including security testing issues and review bottlenecks. Nearly 90% of teams are encountering problems with AI-generated code, which is shifting workload from creation to validation and testing stages. The report emphasizes the urgent need for organizations to operationalize AI governance to mitigate risks and improve efficiency. MSSPs and vendors are recognizing this gap, with companies like Check Point and Pax8 introducing AI security capabilities to help manage AI tools across environments. The findings highlight that governance is not just a compliance issue but a critical ROI multiplier for development teams.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…