Report by Veracode
2026 GenAI Code Security Report
Key Findings
Six of the 11 evaluated models had security pass rates between 50% and 53%.
The best model available still failed nearly one in three security tasks.
AI generates roughly half of all committed code.
Security pass rates by programming language range from Python at 63% down to Java at 30%.
AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.
The average security pass rate for AI-generated code across tracked models was 56%.
Coding-specialized models averaged a 51% security pass rate, compared with 52% for general-purpose models.
OpenAI’s GPT-5.5 achieved a 68% security pass rate.
Models generate compilable code at a near-universal syntax pass rate of approximately 100%.
By model size, large models average a 53% security pass rate, while medium and small models each average 51%.
Alibaba’s Qwen3.7-max recorded a 50% security pass rate, generating vulnerable code every other output in this test.
Reasoning models average a 56% security pass rate versus 51% for non-reasoning models.