AI-Driven Development Outpaces Security Fixes
Enterprise apps see 4.31x more critical vulnerabilities as AI accelerates creation and strains remediation.
The rapid adoption of AI in software development is colliding with enterprise security practices. New analysis from Sonatype shows that enterprise applications now carry 4.31 times more critical and high-severity vulnerabilities than before the acceleration of AI-driven development. The findings point to a widening gap between how quickly code is created and how quickly organizations can secure it.
Four Years of Data
Sonatype analyzed four years of enterprise software development data to reach these conclusions. The company’s report highlights how AI has fundamentally shifted the pace of application creation.
According to Sonatype, application creation has accelerated almost fivefold in the AI era. That surge in output has brought with it a corresponding rise in risk, as the number of critical and high-severity vulnerabilities climbs.
Faster Fixes, But Not Fast Enough
The report also found that the median age of unresolved vulnerabilities has fallen by 59%. This suggests organizations are now addressing vulnerabilities more quickly than before.
However, the faster pace of software creation means that even improved remediation times are insufficient. The volume of new vulnerabilities is growing at a rate that outpaces the gains made in fixing them.
AI Changes the Math
Sonatype attributes the shift directly to the growing use of artificial intelligence in software development. Teams are producing applications at a much faster rate, but that speed carries consequences.
“AI is changing the math of software development. We’re building more software, faster, but we’re also introducing risk faster than traditional security processes can absorb it,” said Brian Fox, co-founder and CTO of Sonatype.
Security Decisions Shift Earlier
Sonatype argues that organizations need to move security decisions earlier in the software assembly process, rather than relying primarily on reviews after development is complete.
“The answer can’t be to put another review step at the end. We need to make better decisions at the moment software is assembled, whether that decision is being made by a developer or an AI agent,” Fox added.
Pressure on Traditional Processes
The report’s authors note that software creation is accelerating faster than traditional security processes can absorb, creating pressure to identify and address risk earlier in development.
This dynamic challenges the conventional approach of bolting on security checks after the fact. It suggests that security must become an integral part of the development pipeline itself.
Developers Stuck in the Middle
The findings place developers in a difficult position, caught between the demand for speed and the need for security.
“Developers shouldn’t have to choose between moving at AI speed and understanding the software they’re bringing into the organization,” said Mitchell Johnson, chief product development officer at Sonatype.
What This Means for Enterprises
For businesses, the takeaway is clear: the risk landscape is evolving faster than many security teams can adapt. The 4.31x increase in critical and high-severity vulnerabilities is not just a statistic—it’s a call to rethink how security is integrated into the software lifecycle.
Organizations that fail to shift security left may find themselves overwhelmed by the volume of risk that AI-driven development introduces. The data suggests that a reactive, end-of-pipeline review process is no longer sufficient.
Sources
- Infosecurity Magazine Original source
Continue Reading
Cursor's Origin Aims at GitHub's Woes
AI startup Cursor, now part of SpaceX, launches Origin, a code-hosting platform that integrates with GitHub amid user frustration over outages.
TikTok's payment push signals super-app ambitions
TikTok is developing a feature to let users send money via DMs, code hidden in its iPhone app suggests, according to a Bloomberg report.
AI-Speed Attacks Force Rethink of Cyber Defense
Experts discuss if detection-first security can keep pace as AI accelerates exploitation and shrinks patch-to-exploit timelines.