Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Infosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets

June 10, 2026

Beyond the Zero-Day: See Your Network Like an Attacker

June 10, 2026

AI Coding Adoption Hits 97% but Governance Lags Behind

June 9, 2026
Facebook X (Twitter) Instagram
Wednesday, June 10
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AI Coding Adoption Hits 97% but Governance Lags Behind
News

AI Coding Adoption Hits 97% but Governance Lags Behind

Team-CWDBy Team-CWDJune 9, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Nearly all software development teams have adopted AI coding assistants, but fewer than a third govern how the tools are used and that gap is capping the productivity AI promises.

The figures come from an independent survey of 831 software engineers and DevOps professionals carried out by the research firm UserEvidence for Black Duck in March 2026. It found 97% actively using the tools but just 30% with a fully governed approach to oversight.

GitHub Copilot and Claude Code dominate, used by 83% and 63% of teams respectively, and most run more than one assistant.

On the upside, 92% of teams credit the assistants with faster, more productive releases and on average the tools hand developers eight hours back each week.

Read more on AI-generated code risks: Most Cyber Leaders Fear AI-Generated Code Will Increase Security Risks

Productivity Comes With a Catch

The gains come with a catch. Nine in 10 teams hit problems with AI-generated code somewhere in their workflow, a sign the tools often shift effort downstream rather than removing it.

Most of the friction lands after the code is written:

  • Manual code review, cited by 52% of teams

  • Security testing, at 51%

  • Reworking the generated code, 48%

  • Iterating on prompts, 41%

Meanwhile, among teams whose AI-written code has surged by more than half, 57% named security testing and vulnerability fixing as the worst bottleneck.

Diana Kelley, CISO at Noma Security, warned that “faster code is not the same thing as safer code,” with developer time shifting toward validating and securing what AI produces.

Governed Teams Pull Ahead

The teams that formalize oversight see the biggest returns. Where AI use is fully governed, 90% report a major efficiency gain, against 58% overall and 44% of teams without full governance.

However, a quarter have no defined AI coding policy at all, and although 68% called automated tracking of AI-generated code extremely important, many still flag it by hand in pull-request comments.

“AI coding assistants are no longer the challenge; governance is,” said Ram Varadarajan, CEO of Acalvio, adding that AI-generated code should be treated as a new supply-chain risk fenced in by policy, secure-coding standards and human review.

Keeping a Human in the Loop

Security unease rises with use. Nearly two-thirds of teams (64%) said they are moderately or extremely concerned the assistants will introduce security defects, and the heaviest users are the most worried.

Despite this, many would welcome automated help: 86% think an AI agent or model should vet AI-written code, and 56% want a dedicated AI security agent. Even so, 84% want to keep a human in the loop via pull requests or in-editor suggestions.

“Security teams need to treat AI-assisted development as part of the attack surface,” warned Nicole Carignan, field CISO at Darktrace, noting that generated code can hide weak authentication, exposed secrets or over-permissioned APIs and often pulls in opaque external dependencies.

In the report, Black Duck made the same case, arguing that the teams which learn to “operationalize AI” will come out ahead, and that guardrails and shared standards are what stop the efficiency gains leaking away as work shifts to QA, DevOps and AppSec.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Next Article Beyond the Zero-Day: See Your Network Like an Attacker
Team-CWD
  • Website

Related Posts

News

Infosecurity Europe: Why JLR’s CISO Enforced In-Person Password Resets

June 10, 2026
News

Beyond the Zero-Day: See Your Network Like an Attacker

June 10, 2026
News

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

June 9, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Fixing trivial passwords is as easy as 123456

May 7, 2026

Here’s how to avoid a ‘second strike’

April 11, 2026

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.