Nine in ten security leaders are concerned about the security risks introduced by AI-generated code, according to new research entitled ‘AI Coding Assistants and the New Security Challenge’ from Salt Security. The report highlights the growing pressure on organizations to govern AI-assisted software development at scale.
Conducted among IT security leaders across the UK and US, the research found that AI coding assistants are now deeply embedded across enterprise development teams, with 67% of organizations reporting widespread adoption. Yet despite rapid uptake, many organizations still lack the governance structures needed to secure AI-generated code effectively.
The findings point to a disconnect between engineering velocity and security oversight. While AI coding tools are accelerating software delivery, organizations continue to rely heavily on manual review processes that were not designed for machine-speed development.
The report also found that larger enterprises face greater operational challenges as AI adoption scales. Organizations with more than 500 employees were significantly more likely to report concerns around enforcement consistency, developer overreliance, and governance complexity across distributed development environments.
The report’s key findings include:
- 90% of security leaders have active concerns about AI-generated code
- 67% say AI coding assistants are now widely adopted across development teams
- 38% still rely primarily on manual review for AI-generated code
- 29% identify insecure coding patterns as the leading risk introduced by AI assistants
- 15% cite misalignment with internal security policies as a major concern
The research warns that manual review alone cannot scale effectively as AI-generated code volumes increase. Reviewer fatigue, inconsistent enforcement, and gaps between policy and practice are creating conditions for what Salt Security describes as ‘security drift’ across development environments.
The report outlines priorities for organizations looking to strengthen governance around AI-assisted development, including improving visibility into AI-generated code, reducing dependence on manual review, standardising secure development practices, and treating AI coding assistants as part of the software supply chain.
Methodology
The research was conducted by Censuswide among 100 IT security leaders across the UK and US between 12 May and 15 May 2026.






