09/18/2025
AI adoption outpaces security
Most organizations are embracing AI in development, yet robust security protocols for AI-generated code are largely absent. This can open the door to new attack vectors. While 76% of respondents check AI code for security risks, only about half evaluate it for quality issues (56%) or IP and license risks (54%). This means a mere 24% perform comprehensive IP, license, security, and quality evaluations for AI-generated code.
Dependency management is key to preparedness
Organizations that are highly effective at tracking and managing open source dependencies are significantly more prepared (85%) to secure open source software compared to the overall average (57%).
Automation drives faster remediation
Of the 294 respondents that perform automatic continuous monitoring, 60% report remediating critical software vulnerabilities within a day. In contrast, only 45% of the full respondent pool remediate critical software vulnerabilities within the same timeframe. This clearly shows that organizations without automatic continuous monitoring are at a significant disadvantage in protecting their software supply chain.