Is Security Losing the Code War?
This is the question that arises from reading Checkmarx’s newly released Future of Application Security in the AI Era report.
Whichever way you lean, it leads to an inevitable conclusion: 2025 may go down as the year that changed AppSec - whether for better or worse remains to be seen.
And yes, at the risk of sounding predictable, it has something to do with AI.
The report’s central thesis is clear: AI is accelerating software development faster than security can react. But perhaps more critically, AI isn’t the cause of the problem—it’s the catalyst. The core issue isn’t AI itself, but how organizations are choosing to absorb its risk without adapting their governance.
Many are knowingly treating that risk as the cost of velocity.
Drawing on insights from 1,500 AppSec leaders, CISOs, and developers globally, the report reveals a troubling trend:
⚠️ 81% admit to knowingly shipping vulnerable code just to meet delivery deadlines. This isn’t a failure of awareness—it’s an accepted trade-off.
And that’s just one signal in a broader breakdown of AppSec oversight:
These numbers paint a stark picture: AppSec programs haven’t just fallen behind—they’ve been, in many cases, sidelined to make room for AI-fueled velocity.
But the issue is that AI-generated code isn’t only a risk multiplier. It’s also an independent risk producer and a new risk surface.
Just earlier this month, reality gave us a reminder of how fast this risk is evolving.
A critical vulnerability in Cursor was exposed, allowing attackers to execute remote code simply through a crafted prompt. The flaw didn’t reside in code written by AI. It lived inside the tool itself.
AI isn’t just expanding the threat landscape. It’s completely terraforming it.
These aren’t theoretical risks. AI-powered development is already producing a new class of vulnerabilities that are pressure-testing organizations’ AppSec readiness:
Taken together, these threats underscore the shift: AI-powered development isn’t just accelerating existing vulnerabilities—it’s creating entirely new attack surfaces that many organizations aren’t yet prepared to defend.
Traditional AppSec controls were never designed for adversaries who can weaponize the development tools themselves. Closing that gap means rethinking governance, embedding security into the developer workflow, and scaling defenses at the same pace as AI-driven code creation.
Beyond AI: The Broader Picture of AppSec Readiness
While AI takes center stage, the report also uncovers broader structural gaps across the AppSec ecosystem:
The takeaway? Awareness is high—but operational readiness hasn’t caught up. Addressing that requires more than tools. It demands better governance, cross-functional alignment, and embedded developer enablement.
Developer Recommendations for the AI Era
Drawing on findings from the report, these five immediate actions can help secure AI-powered software development:
Get the Full Picture
Download the full Future of Application Security in the AI Era report to benchmark where your organization stands—and what steps to take next.
Thanks for checking in with The Monthly CheckUp. In our next edition, we’ll bring you more crisp insights from across the AppSec landscape. Until then, build fast, scan deep, and ship clean!
Check you later,
The Checkmarx Team
Marketing Director, Europe
2moA great read! Chris Ledingham Patrick Siffert Fabien Petiau Pablo Gutt Laura Cleaver Laure Marcos Dan Suleiman Eran Maya
Thanks for sharing