- What: Study shows AI-generated code introduces 15 vulnerabilities on average
- Impact: Risk varies depending on development framework
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources APPLICATION SECURITY СLOUD SECURITY VULNERABILITIES & THREATS THREAT INTELLIGENCE NEWS Choose Wisely: AI-Generated Coding Risk Varies, A Lot AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. Alexander Culafi,Senior News Writer,Dark Reading July 21, 2026 4 Min Read SOURCE: ADVENTTR VIA GETTY IMAGES There may not be a clear winner in terms of which AI model is the best or worst for coding, but there are better (and far worse) models for organizations depending on the development environment or framework one codes in. Software governance firm Secure Code Warrior today unveiled its AI Trust Index, a body of data attempting to quantify the risk established via large language model (LLM)-powered coding tools. AI-assisted development has become exceedingly popular at the organizational level, using tools to generate code, test for vulnerabilities, and audit for general integrity. It is by no means a secret that these tools are expensive, while introducing both vulnerabilities and risk, no matter the efficiency gains. LOADING... While this does not mean organizations should stay away from AI coding tools, it does mean one should be aware of the risks and mitigations before jumping into the deep end. To illustrate some of those risks, the AI Trust Index (introduced as a website) was built on a methodology created with RMIT University and published by Secure Code Warrior. Researchers evaluated 1,760 complete codebases generated by 16 frontier models from vendors including OpenAI, Anthropic, Google, and others. Related:The Real AI Threat Is Blind Trust AI-generated code contained an average of 15 confirmed vulnerabilities per codebase, including 4.3 vulnerabilities rated critical or high severity. More than 27,000 vulnerabilities were identified in total across all codebases. No Clear AI Coding Winner LOADING... Researchers evaluated models based on a 0 to 100 trust score, with 100 meaning the fewest vulnerabilities found in testing the code they generate, relative to other models. As far as the major vendors are concerned, there was no universal winner. Two Anthropic Claude models (Sonnet 5 and Fable 5) scored best (80.4 and 76.4 respectively), while OpenAI GPT 5 Mini ended up in last place (21.6). Overall, OpenAI, Anthropic, and Google frontier models ended up near the top and bottom of the list. That said, it turns out that every AI model has a distinct security fingerprint, according to the report: "Across all evaluated frameworks, models consistently exhibited recurring vulnerability patterns rather than random failures. The SCW AI Trust Index shows each model produces a repeatable mix of OWASP vulnerability categories, enabling organizations to anticipate where security weaknesses are most likely to occur." The most important detail to note is that the strength of a model's performance varies across frameworks; Secure Code Warrior found that a model that performs well in one framework (such as Django or React) may offer a mediocre performance in another, or even miss controls altogether. For example, Claude Opus 4.8 got a 100 Trust Index score when tested against Django, but a just garnered a 57.3 in C-Basic and a 28.5 in C#-Basic. Related:2-Click Cursor Exploit Enables Dev Environment Takeover Ultimately, the results showed that the zoomed-out overall trust score matters less than which model is paired with which framework; 11 development frameworks were tested in all. Researchers also found that there was little to no correlation between model usage cost and security; that the most common security failures resulted from things models forgot to do (authentication checks and input validation) rather than actively dangerous code; and that risk was overall predictive rather than random. Specifically, the model and framework combination made it more or less predictable how many (and which kind of) vulnerabilities researchers would find. Consider Your Frameworks & Prioritize Training for High-Risk Environments Secure Code Warrior CEO and co-founder Pieter Danhieux tells Dark Reading that, according to the data, the highest-scoring frameworks were 40 times less risky than the lowest-scoring ones. JavaScript and Java EE/JSP carried much of the exposure, while C# and Java Spring "barely registered." Related:Cursor IDE Auto-Executes Malicious Code in Poisoned Repos "You can't personally audit (nor override) every team's framework choice, but you can require that any team building in a high-risk environment have a security gate and training requirements in place before it ships, the same way you'd require extra scrutiny for any other high-risk system in your environment," he says. He also recommends that organizations prioritize their training investments around the actual universal situations, rather than trying to cover every situation a developer may run into. "We found 17 CWEs that showed up in every one of the 16 models we tested. That's too long a list to mandate all at once, so we'd tell a CISO to prioritize the five that carry the most volume: sensitive data leaking into logs, cross-site scripting, hard-coded credentials, predictable session tokens and reset codes, and path traversal," he says. "None of these is a new, insurmountable threat vector. AppSec teams have had playbooks for all five for years. The job now is making sure those playbooks get pointed at AI-generated code with the same rigor as anything else, which is a requirement you can set from the top without writing a line of code yourself." About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos More Webinars You May Also Like APPLICATION SECURITY Supply Chain Attack Secretly Installs OpenClaw for Cline Users by Rob Wright FEB 19, 2026 APPLICATION SECURITY Chinese Hackers Hijack Notepad++ Updates for 6 Months by Jai Vijayan FEB 02, 2026 APPLICATION SECURITY Trump Administration Rescinds Biden-Era Software Guidance by Alexander Culafi JAN 29, 2026 APPLICATION SECURITY Microsoft Fixes Exploited Zero Day in Light Patch Tuesday by Jai Vijayan DEC 09, 2025 Editor's Choice VULNERABILITIES & THREATS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes byJai Vijayan JUL 14, 2026 5 MIN READ PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices