Sonatype Study Reveals AI Models Require Real-Time Intelligence for Safe Software Recommendations
Article Content
Sonatype's research published on March 24, 2026, indicates that larger AI models alone do not yield the safest software dependency recommendations. The study assessed approximately 37,000 open source upgrade recommendations and found that AI models grounded in real-time software intelligence significantly reduced Critical and High risk vulnerabilities compared to ungrounded models from Anthropic, Google, and OpenAI. It was noted that larger models, while improving in reasoning, often recommended 'no change' to components, leaving significant vulnerabilities unaddressed. The findings emphasize that effective AI-assisted software dependency decisions depend on real-time intelligence that validates package availability and assesses upgrade paths. This research builds on the 2026 State of the Software Supply Chain report, highlighting the importance of grounding AI in live data for credible and safe recommendations. The study analyzed direct dependencies from enterprise applications scanned between June and August 2025, focusing on popular repositories like Maven, npm, PyPI, and NuGet.
Key Points: • AI models grounded in real-time intelligence outperform larger models without context. • Over 37,000 software upgrade recommendations were analyzed in the study. • Larger models often recommended 'no change', leaving critical vulnerabilities unaddressed.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.