AGP Picks
View all

AI-written code carries 4.4x more security flaws than human code, study finds

Aug. 20, 2026
By AI, Created 17:00 UTC, Aug 20, 2026, AGP -

State of Cyber, the research lab of Symbiotic Security, analyzed nearly 2,000 GitHub repositories and more than 1,000 AI-built apps and found materially higher vulnerability rates in code assisted by AI. The findings suggest security teams need to move checks earlier in the development process as AI speeds up software creation.

Why it matters: - AI-assisted software is shipping more vulnerabilities into production, raising the odds of exposed data, broken access controls and other security failures. - The findings matter for teams adopting vibe coding and AI coding assistants at scale, because faster development is outpacing traditional review processes. - Security leaders may need to shift from post-build review to checks during code generation and editing.

What happened: - State of Cyber, the research lab of Symbiotic Security, published AI vs Humans: Security at Scale after a three-month study. - The lab analyzed 1,967 public GitHub repositories and 1,072 vibe-coded applications across five popular platforms. - The team ran 10 independent security scanners across the full dataset. - The study found 87,826 vulnerabilities across the repositories and apps.

The details: - AI-assisted repositories averaged 42.3 vulnerabilities each. - Human-written repositories averaged 9.6 vulnerabilities each. - That means AI-assisted code carried 4.4 times more vulnerabilities on average. - 70.5% of AI-assisted repositories had at least one security issue. - 50.4% of human-only repositories had at least one security issue. - The repository review covered 104 different vulnerability types. - The app audit focused on 1,072 live apps built with AI vibe-coding tools on Supabase. - 98% of those apps had at least one vulnerability. - 29% carried a high or critical issue. - 16% let a stranger delete or change data without login credentials. - The app review found 6,185 vulnerabilities in total, or 5.9 per app on average. - The study says data was collected between January and March 2026 through automated pipelines at scale. - The work was handled under responsible disclosure, and no data was exfiltrated, stored or shared beyond what was needed to document and report each vulnerability. - The full findings are published at state-of-cyber.org.

Between the lines: - Vibe coding reduces the barrier to launching software, but it also lowers the barrier to launching insecure software. - The research points to a structural problem: code is being produced faster than security teams can inspect it after deployment. - The article argues the gap is not just about volume; AI-generated code also spans a wider range of flaw types. - The report frames the issue as a tooling problem, not a reason to stop using AI for development.

What's next: - Security teams are likely to push more scanning, guardrails and review into the coding moment itself. - Organizations using AI to accelerate development will need to decide how to catch vulnerabilities before code reaches production. - The study adds pressure on vendors and internal teams to build safer AI-assisted development workflows.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

World Online News Reports

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

World Online News Reports

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.