Report by Checkmarx

2027 Outlook Report: The Future of Application Security in the Era of AI

11 FINDINGSPublished Jun 8, 2026
View Original Report →

Key Findings

Within one year, the share of organizations knowingly shipping vulnerable code decreases from 81% to 75%.

Application SecurityVulnerable Code

96% of developers acknowledge having AI tooling integrated in their IDEs.

Application SecurityDeveloper ToolsAI Tooling

Companies with 81–100% AI-generated production code ship software with known security vulnerabilities at a 47% rate compared with 14% for companies with 1–20% AI-generated production code, making them nearly three times more likely.

Application SecurityAI CodeSoftware Vulnerabilities

18% of developers apply security continuously as they write code.

Application SecurityDeveloper PracticesSecure Coding

95% of CISOs feel pressure to suppress or delay compliance-related security issues when business deadlines are at stake.

Application SecurityGovernanceExecutive RiskCompliance

75% of organizations knowingly deploy vulnerable code at some point.

Application SecurityVulnerable CodeRisk Management

Within one year, the proportion of companies with formal AI governance policies increases from 18% to 22%.

AI GovernanceApplication Security

93% of organizations acknowledge a recent breach tied to their own applications.

Application SecurityData BreachIncident Response

73% of organizations describe their security posture as 'advanced' or 'highly mature'.

Application SecuritySecurity PostureRisk Perception

78% of organizations lack formal AI governance policies.

AI Governance

More than 80% of developers do not apply application security continuously as code is written.

Application SecurityDeveloper PracticesSecure Coding