Black Duck
Reports
All Statistics
48% of development teams experience bottlenecks in code rework related to AI-generated code.
Teams with full governance for AI coding assistants in place are 55% more likely to report a major improvement in efficiency.
64% of development teams express moderate or extreme concern about AI coding assistants introducing security defects or vulnerabilities.
98% of codebases contain open source components.
Mean vulnerabilities per codebase increased by 107% year-over-year.
Open source component counts increased by 30% year-over-year.
76% of organizations check AI code for security risks.
Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.
63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.
31.5% of organizations produce SBOMs due to industry regulations.
96.1% of organizations are integrating open source AI models into their products.
18% of companies are affected by "Shadow AI".
91% of audited applications contain outdated open source software components.
86% of audited applications contained open source vulnerabilities, with 81% containing high- or critical-risk vulnerabilities.
64% of open source components were transitive dependencies.
Automated verification of infrastructure security surged by more than 50%.
Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.
Nearly 30% more organizations now produce SBOMs to meet transparency requirements.
The number of organisations conducting adversarial tests (abuse cases) has doubled year-on-year.
The number of organisations employing research groups to develop new attack methods has grown by 30%.
There has been a 67% increase in the number of organisations performing software composition analysis (SCA) on code repositories.
Developers reclaim an average of eight hours per week when using AI coding assistants.
Nearly 90% of development teams encounter issues with AI-generated code.
86% of development professionals believe an AI agent or model should evaluate AI-generated code.
56% of development professionals prefer a dedicated AI security agent separate from the code-generation tool to evaluate AI-generated code.
30% of development professionals believe the same AI model that generated the code should also review it for security issues.
84% of developers prefer to keep a human in the loop via pull requests or real-time IDE suggestions when using AI-assisted development.
AI coding assistants have 97% adoption among enterprise development teams.
97% of development teams have adopted AI coding assistants.
92% of development teams report improved productivity and release velocity when using AI coding assistants.
30% of development teams have full governance in place for AI coding assistant adoption and oversight.
51% of development teams experience bottlenecks in security testing related to AI-generated code.
53% of development teams have grown total code volume by over 25%.
52% of development teams experience bottlenecks in manual review related to AI-generated code.
68% of developers say it is extremely important to have a clear, automated system for tracking AI-generated code and measuring its impact for debugging, security, and accountability.
58% of development teams cite a major improvement in productivity and release velocity from AI coding assistants.
Developers will spend 29% more time reviewing and validating AI-generated code, 29% more time on complex architecture and system design, and 23% more time on security verification and risk management.
76% of organizations check AI-generated code for security risks.
54% of organizations evaluate AI-generated code for IP and license risks.
56% of organizations assess quality issues in AI-generated code.
The number of files per codebase grew by 74% year-over-year.
68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.
24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.
60% of organizations that perform automatic continuous monitoring report remediating critical software vulnerabilities within a day.
Only 24% of organizations have adopted comprehensive strategies to secure AI-generated code.
35% of respondents cite interpreting and operationalizing complex regulatory requirements as their biggest challenge.
Only 45% of the full respondent pool say they remediate critical software vulnerabilities within a day.
59% of respondents that prioritize SBOM validation typically respond to critical software vulnerabilities within one day.
95% of surveyed organizations reported using AI tools in software development.
54% of organizations using at least four compliance controls remediate critical vulnerabilities within a day.