Black Duck
Reports
All Statistics
48% of development teams experience bottlenecks in code rework related to AI-generated code.
Teams with full governance for AI coding assistants in place are 55% more likely to report a major improvement in efficiency.
64% of development teams express moderate or extreme concern about AI coding assistants introducing security defects or vulnerabilities.
98% of codebases contain open source components.
Mean vulnerabilities per codebase increased by 107% year-over-year.
Open source component counts increased by 30% year-over-year.
76% of organizations check AI code for security risks.
Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.
63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.
31.5% of organizations produce SBOMs due to industry regulations.
96.1% of organizations are integrating open source AI models into their products.
18% of companies are affected by "Shadow AI".
91% of audited applications contain outdated open source software components.
97% of all applications evaluated contained open source software.
33% had open source software components with no license or a customized license.
Automated verification of infrastructure security surged by more than 50%.
Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.
Nearly 30% more organizations now produce SBOMs to meet transparency requirements.
There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.
The number of organisations employing research groups to develop new attack methods has grown by 30%.
A 22% rise in the number of organizations creating software bills of materials (SBOMs) for deployed software has been observed.
Developers reclaim an average of eight hours per week when using AI coding assistants.
Nearly 90% of development teams encounter issues with AI-generated code.
56% of development professionals prefer a dedicated AI security agent separate from the code-generation tool to evaluate AI-generated code.
86% of development professionals believe an AI agent or model should evaluate AI-generated code.
30% of development professionals believe the same AI model that generated the code should also review it for security issues.
84% of developers prefer to keep a human in the loop via pull requests or real-time IDE suggestions when using AI-assisted development.
AI coding assistants have 97% adoption among enterprise development teams.
92% of development teams report improved productivity and release velocity when using AI coding assistants.
97% of development teams have adopted AI coding assistants.
30% of development teams have full governance in place for AI coding assistant adoption and oversight.
51% of development teams experience bottlenecks in security testing related to AI-generated code.
53% of development teams have grown total code volume by over 25%.
52% of development teams experience bottlenecks in manual review related to AI-generated code.
68% of developers say it is extremely important to have a clear, automated system for tracking AI-generated code and measuring its impact for debugging, security, and accountability.
58% of development teams cite a major improvement in productivity and release velocity from AI coding assistants.
Developers will spend 29% more time reviewing and validating AI-generated code, 29% more time on complex architecture and system design, and 23% more time on security verification and risk management.
76% of organizations check AI-generated code for security risks.
54% of organizations evaluate AI-generated code for IP and license risks.
56% of organizations assess quality issues in AI-generated code.
68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.
24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.
The number of files per codebase grew by 74% year-over-year.
60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.
Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.
35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.
Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.
59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.
95% of surveyed organizations reported using AI tools in software development.
54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.