AI-generated code is in vogue: Developers are now packing codebases with automated code – but they’re overlooking security and leaving enterprises open to huge risks
A host of big tech companies are relying on AI-generated code, and developers globally are following suit
Nearly half of developers using AI to support operations say their codebases are now largely AI-generated, new research shows.
A survey from Cloudsmith found 42% of developers admitted to having AI-filled codebases, with respondents noting that the use of AI has helped them markedly improve productivity and efficiency.
Yet despite the influx of AI-generated code, long-standing best practices are being overlooked, the study warned. Just over two-thirds (67%) of developers said they review code before deployments, raising concerns over software security.
Glenn Weinstein, CEO at Cloudsmith, said the use of AI in software development does present opportunities for development teams, but warned against placing complete faith in AI.
“Software development teams are shipping faster, with more AI-generated code and AI agent-led updates,” he said.
“AI tools have had a huge impact on developer productivity, which is great. That said, with potentially less human scrutiny on generated code, it’s more important that leaders ensure the right automated controls are in place for the software supply chain.”
The study noted that a growing number of developers are not only becoming reliant on AI-generated code, but are also placing a greater degree of trust in code written by AI tools.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Around 20% said they trust AI-generated code “completely”, the study found.
Notably, there are those in the profession taking a more considered approach to the use of AI in code generation. More than half (59%) said they apply additional scrutiny to AI-generated packages, for example, but a gap on enforcement is emerging at some enterprises.
Around 17% said they have no control policies in place over the use of AI in development processes, or for the use of AI-generated code. Similarly, roughly one-third (34%) noted they use tools that enforce policies specific to AI-generated packages, but this still leaves a glaring gap and could leave them open to threats.
The rise of generative AI and its use in software development has been mirrored by a significant rise in “AI-specific exploits”, Cloudsmith noted. Among those highlighted in the study were ‘slopsquatting’, whereby attackers weaponize hallucinated package names suggested by coding assistants.
Developers and security practitioners alike also voiced concerns over their ability to spot potential exploits of flaws, with just 29% stating they feel “very confident” in their ability to detect vulnerabilities.
This is particularly risky when working with open source libraries, the study warned, where AI tools are likely to draw suggestions.
AI-generated code is in vogue
The use of AI-generated code has become a big talking point in the tech industry over the last year, with some leading companies having turned to the trend to speed up development.
In November last year, Google CEO Sundar Pichai revealed that around a quarter of the tech giant’s internal source code was AI-generated, and that’s likely increased since then.
Speaking during an earnings call at the time, Pichai said Google was using AI across development teams both to speed up coding processes and to reduce manual toil for developers.
Notably, Pichai insisted that all AI-generated code was subject to robust safety checks by human workers. Engineers are often kept in the loop to review this code, he noted.
Microsoft has also jumped on the bandwagon in this regard. During an appearance at Meta’s LlamaCon conference in April, CEO Satya Nadella told Mark Zuckerberg up to 30% of its code was written with AI.
“I’d say maybe 20%, 30% of the code that is inside of our repos today and some of our projects are probably all written by software,” Nadella told Zuckerberg.
Nadella expects the volume of AI-generated code at the company to also steadily increase in the coming years.
MORE FROM ITPRO
- Half of developers want to quit over "embarrassing" tech stack
- Shifting left might improve software security, but developers are becoming overwhelmed
- AI coding tools are finally delivering results for enterprises

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Broadcom eyes security, performance boosts with vDefend and Avi Load Balancer updatesNews Enhancements to VMware vDefend and VMware Avi Load Balancer use AI-powered automation to help secure private cloud environments
-
How business leaders are using the Dell Pro 7 and Dell Pro 5Sponsored Thanks to flexibility and a range of spec options, the Dell Pro 7 and Pro 5 laptops can suit a variety of business leaders across a mix of workplaces
-
Red Hat launches new open source project to drive AI governanceNews The asago open source project will allow enterprises to automate compliance processes and bolster security
-
Amazon targets agent safety gains with investment in team behind Lean programming languageNews The tech giant hopes support for the open source programming language could drive AI agent safety improvements
-
‘These Chinese models are excellent’: Nvidia CEO Jensen Huang hails powerful new Chinese AI models like Kimi K3 – and says don’t be put off by security ‘misconceptions’News As powerful new AI models like Kimi K3 hit the market, Huang says competition will be a positive for the global industry
-
Apple is speeding up software patching due to AI security concerns – here’s what you need to knowNews Apple is speeding up its software patching processes amid rising concerns that AI is helping hackers to spot and exploit flaws at a far quicker pace.
-
Enterprises are shipping so much AI-generated code they can't control or secure itNews As AI coding becomes commonplace, organizations are struggling to control what they are shipping
-
The UK is betting big on the power of open source AINews The government wants to encourage open source developers to help improve public services
-
‘Open source should rest on transparency, not deception’: Euro-Office ‘sovereignty’ claims questioned in scathing open letter by LibreOffice maintainersNews The developers behind LibreOffice have questioned Euro-Office’s sovereignty credentials and use of a Microsoft-based document format
-
AI might help speed up software development, but 81% of devs now spend more time reviewing code – and it’s creating an ‘invisible work’ trend that’s pushing teams to the limitNews While AI is improving productivity and efficiency, many developers are caught up in a vicious cycle of code reviews and bug hunting