Report by Checkmarx

The Future of AppSec in the Era of AI

12 FINDINGSPublished Aug 14, 2025
View Original Report →

Key Findings

Fewer than half of the CISOs, AppSec managers and developers report deploying foundational security tools like dynamic application security testing (DAST) or infrastructure-as-code scanning.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIDASTInfrastrucutre-as-code scanning

Just 51% of North American organisations report adopting DevSecOps

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIDevSecOps

Only half of organisations surveyed actively use core DevSecOps tools.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIDevSecOps

34% of CISOs, AppSec managers and developers admit that more than 60% of their code is AI-generated.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAI coding assistant

98% of organisations experienced a breach stemming from vulnerable code in the past year.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIVulnerable codeBreach

Within the next 12 to 18 months, nearly a third (32%) of CISOs, AppSec managers and developers expect Application Programming Interface (API) breaches via shadow APIs or business logic attacks.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAPIShadow APIsBusiness logic attackBreach

Only 18% of organisations have policies governing AI use.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAI policy

Up to 60% of code is being generated by organisations using AI coding assistants.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAI coding assistant

20% of organisations still forbid the use of AI coding assistants.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAI coding assistant

81% of organisations knowingly ship vulnerable code.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIVulnerable code

Half of CISOs, AppSec managers and developers already use AI security code assistants.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIAI coding assistant

81% of organisations knowingly ship vulnerable code.

CheckmarxThe Future of AppSec in the Era of AI·Aug 14, 2025
AIVulnerable code