Urgent.News

What's breaking now, across thousands of outlets.

AI

AI coding is putting software risk on steroids

AI accelerates software development, but can security and governance keep pace with rising risk?

AI coding is putting software risk on steroids

Artificial intelligence has revolutionized software development, enabling tasks that once took days to complete within mere hours through generative AI tools. This speed, while promising for innovation and productivity, has introduced a significant challenge in software security. The rapid pace of AI-assisted development has outpaced existing security, governance, and risk management processes, creating a growing imbalance between the speed of software creation and the pace of software remediation.

As organizations rush to build and deploy software faster than ever, they are inadvertently expanding the attack surface through the integration of open-source components, APIs, and third-party services. This expansion amplifies software complexity, making it increasingly difficult to maintain security. Veracode's 2026 State of Software Security report revealed that 82% of organizations carry unresolved security vulnerabilities, with 60% experiencing critical security debt—flaws severe enough to cause significant damage if exploited. Notably, 66% of the most dangerous, long-lived vulnerabilities stem from third-party code.

The issue lies not in the inherent flaw of AI-generated code, but in the fact that it allows organizations to accelerate software creation beyond the capacity of current security governance structures. Traditional security governance, designed for slower development cycles, struggles to keep up with the machine-speed development enabled by AI. When software generation, modification, and deployment occur at machine speed, governance models reliant on human intervention become unsustainable.

To address this, security leaders must rethink governance for the AI era. The goal should not be to inspect every line of code or eliminate every vulnerability before deployment, as this approach was already unsustainable before the advent of generative AI. Instead, organizations need governance systems capable of operating at the same pace as software creation.

This involves automating risk analysis, continuously evaluating dependencies, enforcing policies through pipelines, and prioritizing remediation based on business risk. Governance becomes the new trust layer, providing visibility, control, and accountability in an increasingly complex software ecosystem.

While AI can generate software, it cannot assume responsibility for its security. Boards, regulators, and customers will still expect organizations to demonstrate secure and resilient software. The challenge for organizations is not just to build software faster, but to govern it effectively. Those that can manage this balance will lead in the AI era, demonstrating that they can trust the software they build.

AI is a powerful tool, but its impact on software risk requires a corresponding boost in governance to ensure responsible and secure software development.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in AI

The 2 a.m. AI interview is how companies stopped interviewing back

Last month I had a job interview at 2 a.m. The interviewer didn't blink, didn't nod, and didn't let me ask a single question back. Well, the room was empty.

  • AI interview conducted at 2 a.m. with no human presence
  • 25% of Ribbon AI interviews scheduled between 10 p.m. and 2 a.m.
  • 38% of U.S. job seekers drop out due to AI interview involvement

More from Wednesday 26 August →