Report by Pentest Tools
The shrinking validation window
Key Findings
30.3% of developers at enterprises disagree or strongly disagree with the statement “I have sufficient time to thoroughly review AI-generated code before deployment.” 48.1% say they do have enough time. The remaining 21.6% are neutral.
20% of developers at enterprises see post-deployment vulnerabilities in AI-assisted code “always” or “often.” Another 31.1% see this “sometimes.” Combined: 51.1% of respondents experience this regularly. Just under one in five (19.9%) say it never happens to them.
Only 8.7% of developers at enterprises say vulnerabillity testing keeps pace completely. 41.5% say it keeps pace most of the time. 35.7% say it sometimes falls behind, and 9.5% say it frequently does.
71.7% of developers at enterprises say they always (45.6%) or often (26.1%) examine AI-generated code for vulnerabilities before integrating it.
When asked whether developers at enterprises have sufficient time to review AI-generated code thoroughly, 30.3% disagreed. Another 21.6% were neutral.
Only 8.7% of developers at enterprises say vulnerability testing keeps pace with AI-generated code.
20% of developers at enterprises say vulnerabilities surface in AI-assisted code post-deployment “always” (1.7%) or “often” (18.3%). 31.1% say it happens sometimes. 28.6% say rarely, and 19.9% say never.
76.4% of respondents at enterprises use AI coding tools “always” (41.5%) or “usually” (34.9%) in their development work. Only 5.4% use them rarely or sometimes.
82.2% of developers work at enterprises that enforce, strongly encourage, or informally encourage AI tool use. The “allowed but not encouraged” cohort is 8.3%. Cautious encouragement sits at 9.5%.
76% of developers at enterprises always or usually use AI for coding.