Report by Checkmarx
2027 Outlook Report: The Future of Application Security in the Era of AI
Key Findings
Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.
96% of developers acknowledge having AI tooling integrated in their IDEs.
Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.
18% of developers apply security continuously as they write code.
95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.
75% of organizations knowingly deploy vulnerable code at some point.
Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.
93% of organizations acknowledge a recent breach tied to their own applications.
73% of organizations describe their security posture as 'advanced' or 'highly mature'.
78% of organizations lack formal AI governance policies.
More than 80% of developers do not apply application security continuously as code is written.