The Hidden Cost of AI Coding Tools: Security Gaps, Leaked Secrets, and a Bill That Keeps Growing
New research shows AI coding assistants leak sensitive credentials at twice the normal rate, routinely produce flawed code, and may cost more than a developer's salary within three years.

Key points
- 91% of organisations used two or more AI coding tools as of GitLab's 2026 AI Accountability Report, published last month.
- 96% of developers surveyed by SonarSource in 2026 said they don't trust AI-generated code to be correct without human review.
- GitGuardian research found Claude Code-assisted commits leaked sensitive credentials at 3.2%, more than double the 1.5% baseline across all public GitHub commits.
- Georgia Tech's Vibe Security Radar project tracked 35 CVEs attributable directly to AI coding tools as of March 2025.
- A Gartner report projects AI coding costs will exceed the average developer's salary by 2028 as token charges rise.
AI coding assistants, software tools that write or suggest code on a developer's behalf, have swept through the technology industry faster than almost anyone predicted. GitLab's 2026 AI Accountability Report, published last month, found 91% of organisations now use at least two of these tools. A Black Duck survey put enterprise adoption at 97%.
The productivity numbers look good on paper. Developers in SonarSource's 2026 survey of 1,149 respondents reported an average 35% productivity gain. But 96% of those same developers don't trust the code these tools produce without checking it themselves, and only 48% said they always do that check before code ships.
That gap is where the real damage happens.
When unchecked code reaches a live system, it can carry flawed logic or exposed credentials straight into a company's products. Veracode found 45% of AI-generated code samples contained vulnerabilities from the OWASP Top 10, a widely used catalogue of critical software security weaknesses.
How does AI code actually put a company at risk?
The most immediate danger is leaked credentials: passwords, secret keys, or access tokens accidentally embedded in the code itself. Ben MartinMooney, product marketing manager at GitGuardian, told Dark Reading that AI coding assistants increase the rate at which secrets appear in code by roughly 40%. At the commit level, Claude Code-assisted commits leaked secrets at 3.2% versus a 1.5% baseline across public GitHub commits. Once a credential is exposed in a public repository, remediation requires rotating the password, tracing every system it touched, and coordinating across teams. GitGuardian's own calculator puts the minimum at two engineer hours per incident, rising sharply if the credential is already live in production. Most companies never fully clean up: 64% of credentials confirmed valid in public GitHub commits in 2022 were still active when retested in January 2026.
Wiz this week disclosed GhostApproval, a vulnerability pattern affecting six major AI coding assistants, among them Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, and Windsurf. As we reported on 9 July, a malicious repository can trick an AI agent into reading files outside its permitted workspace, potentially letting attackers run harmful code on a developer's machine. AWS, Cursor, and Google have issued fixes; three others had not patched the issue at time of publication.
There's also the problem researchers call "slopsquatting." AI tools sometimes invent the names of software packages that don't exist. Criminals publish harmful software under those invented names, waiting for developers to install them. Roughly 20% of AI-generated code samples reference these phantom packages.
Should you worry about the cost?
Costs keep climbing too. Base pricing runs from 19 to 40 US dollars per user per month before computing token charges, and premium tiers reach 60 to 200 dollars. A recent Gartner report concluded that rising token costs will push AI coding expenses past the average developer's salary by 2028. Security teams report spending up to 40% of their time on alerts that prove to be false positives, overhead that Chao Cheng-Shorland, CEO of ShelterZoom, described to Dark Reading as "producing nothing."
The blunt read on all of this: the productivity gains are real, but they're partly funding a hidden security and remediation bill that most finance teams haven't priced in yet. Ask your development team whether human review is mandatory before code ships and whether credential scanning runs on every commit. Those two controls catch the most common failures.



