Knowingly Shipping Vulnerable Code Has Become Standard Practice, Survey Finds
A Checkmarx survey of 2,350 security leaders finds nearly half of production code is AI-generated — and enterprises are deploying it despite knowing it carries unresolved flaws.

Three-quarters of enterprises now knowingly deploy vulnerable code. That figure comes from a Checkmarx survey of 2,350 CISOs, AppSec managers, and developers across 14 countries, released this month. The findings describe an industry that has normalized risk, not reduced it.
Nearly half of production code is AI-generated today. Enterprises that put AI-generated code at 81–100% of their output ship vulnerable code 3.4 times more frequently than organizations keeping AI-assisted code at or below 20%. Seventy percent of developers reported that AI code generation introduced vulnerabilities in 2025. Ninety-three percent of surveyed enterprises experienced at least one security breach directly attributable to an internally developed application.
About 30% of respondents admitted they ship compromised code and simply hope the flaw goes undetected. More than a third leave at least half of their known vulnerabilities unpatched for 90 days or more. The survey was conducted before Anthropic's Mythos model became publicly discussed — a timing note the report flags explicitly — yet the data already reflects an acceleration problem that Mythos has since made sharper. The report states that Mythos-class models "collapse the window between a vulnerability existing and a working exploit being available from months to minutes."
The bottleneck is not detection. Checkmarx is direct on this point: the bottleneck is "the human decision to ship anyway, suppress the finding, or defer to the next sprint." AppSec teams operate mostly in reactive mode. Developers use security tooling but apply it continuously only 18% of the time. Pressure to deliver forces speed over security — and then developers absorb the blame in post-mortems and performance reviews when things fail.
The self-assessment problem compounds the underlying one. Among organizations rating themselves "highly mature" on AI security, 42% ship among the most vulnerable code. Their breach rates are "barely distinguishable" from less confident peers. Only 22% of organizations surveyed have formal AI governance in place. Manual code review remains the dominant compliance mechanism.
Checkmarx identifies four areas requiring structural change: prioritizing risk over code volume, embedding security controls into IDE and pipeline workflows rather than staging them as checkpoints, consolidating fragmented tool stacks with clear ownership, and replacing manual triage with automated remediation that does not require human approval at each step.
The governance gap may carry regulatory consequences that the survey does not fully surface. Under SEC Rules 13a-15 and 15d-15, public companies must evaluate and disclose the effectiveness of disclosure controls — and known, unremediated vulnerabilities in production systems are material information. Deliberately deferring patches while executives certify effective controls is a narrow lane to walk. CIRCIA's forthcoming final rulemaking on covered cyber incident reporting will add another layer of obligation for critical infrastructure entities. The survey data suggests many organizations are not positioned for either.



