惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
GbyAI
GbyAI
M
MIT News - Artificial intelligence
美团技术团队
罗磊的独立博客
雷峰网
雷峰网
量子位
博客园 - 【当耐特】
Last Week in AI
Last Week in AI
D
Docker
小众软件
小众软件
S
SegmentFault 最新的问题
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
WordPress大学
WordPress大学
V
V2EX
博客园_首页
腾讯CDC
The Cloudflare Blog
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
AI Coding Adoption Hits 97% but Governance Lags Behind
Alessandro Mascellino · 2026-06-09 · via www.infosecurity-magazine.com

Written by

Nearly all software development teams have adopted AI coding assistants, but fewer than a third govern how the tools are used and that gap is capping the productivity AI promises.

The figures come from an independent survey of 831 software engineers and DevOps professionals carried out by the research firm UserEvidence for Black Duck in March 2026. It found 97% actively using the tools but just 30% with a fully governed approach to oversight.

GitHub Copilot and Claude Code dominate, used by 83% and 63% of teams respectively, and most run more than one assistant.

Credit: Black Duck.
Credit: Black Duck.

On the upside, 92% of teams credit the assistants with faster, more productive releases and on average the tools hand developers eight hours back each week.

Read more on AI-generated code risks: Most Cyber Leaders Fear AI-Generated Code Will Increase Security Risks

Productivity Comes With a Catch

The gains come with a catch. Nine in 10 teams hit problems with AI-generated code somewhere in their workflow, a sign the tools often shift effort downstream rather than removing it.

Most of the friction lands after the code is written:

  • Manual code review, cited by 52% of teams

  • Security testing, at 51%

  • Reworking the generated code, 48%

  • Iterating on prompts, 41%

Meanwhile, among teams whose AI-written code has surged by more than half, 57% named security testing and vulnerability fixing as the worst bottleneck.

Diana Kelley, CISO at Noma Security, warned that "faster code is not the same thing as safer code," with developer time shifting toward validating and securing what AI produces.

Governed Teams Pull Ahead

The teams that formalize oversight see the biggest returns. Where AI use is fully governed, 90% report a major efficiency gain, against 58% overall and 44% of teams without full governance.

Credit: Black Duck.
Credit: Black Duck.

However, a quarter have no defined AI coding policy at all, and although 68% called automated tracking of AI-generated code extremely important, many still flag it by hand in pull-request comments.

"AI coding assistants are no longer the challenge; governance is," said Ram Varadarajan, CEO of Acalvio, adding that AI-generated code should be treated as a new supply-chain risk fenced in by policy, secure-coding standards and human review.

Keeping a Human in the Loop

Security unease rises with use. Nearly two-thirds of teams (64%) said they are moderately or extremely concerned the assistants will introduce security defects, and the heaviest users are the most worried.

Despite this, many would welcome automated help: 86% think an AI agent or model should vet AI-written code, and 56% want a dedicated AI security agent. Even so, 84% want to keep a human in the loop via pull requests or in-editor suggestions.

"Security teams need to treat AI-assisted development as part of the attack surface," warned Nicole Carignan, field CISO at Darktrace, noting that generated code can hide weak authentication, exposed secrets or over-permissioned APIs and often pulls in opaque external dependencies.

In the report, Black Duck made the same case, arguing that the teams which learn to "operationalize AI" will come out ahead, and that guardrails and shared standards are what stop the efficiency gains leaking away as work shifts to QA, DevOps and AppSec.

You may also like

What’s Hot on Infosecurity Magazine?