4× Development Velocity, 10× More Vulnerabilities: The AI Coding Paradox

A recent Apiiro study published on September 4, 2025, reveals that enterprises using AI coding assistants are experiencing vastly increased development speed, producing three to four times more commits than teams without such tools. However, these commits are bundled into fewer but much larger pull requests, which makes thorough review difficult and increases the potential blast radius of errors. Apiiro’s analysis of Fortune 50 codebases shows a tenfold surge in security issues in AI-generated code compared to December 2024, with over 10,000 new security findings per month by June 2025. While syntax errors dropped by 76 percent and logic bugs by over 60 percent, architectural flaws like privilege escalation paths rose 322 percent, and design flaws by 153 percent. AI-assisted developers also exposed cloud credentials nearly twice as often as others due to multi-file changes that can propagate risks unnoticed. The findings point to the conclusion that without equally robust, AI-powered application security (AppSec), organizations risk scaling vulnerabilities at the same pace as productivity improvements. 

https://apiiro.com/blog/4x-velocity-10x-vulnerabilities-ai-coding-assistants-are-shipping-more-risks/

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

KEVIntel: Real-Time Intelligence on Exploited Vulnerabilities

OWASP SAMM Skills Framework Enhances Software Security Roles