Report by Veracode

2026 GenAI Code Security Report

12 FINDINGSPublished Jul 28, 2026
View Original Report →

Key Findings

Models generate compilable code at a near-universal syntax pass rate of approximately 100%.

Code QualityAI Code GenerationAI Coding

OpenAI’s GPT-5.5 achieved a 68% security pass rate.

LLMsAI Code Security

Coding-specialized models averaged a 51% security pass rate, compared with 52% for general-purpose models.

Model ArchitectureAI Code SecurityAI CodingLLMs

By model size, large models average a 53% security pass rate, while medium and small models each average 51%.

AI Code SecurityAI Coding

The average security pass rate for AI-generated code across tracked models was 56%.

AI Code SecurityApplication SecurityAI Coding

Alibaba’s Qwen3.7-max recorded a 50% security pass rate, generating vulnerable code every other output in this test.

AI Code SecurityModel EvaluationAI Coding

Reasoning models average a 56% security pass rate versus 51% for non-reasoning models.

AI Code SecurityAI Coding

Security pass rates by programming language range from Python at 63% down to Java at 30%.

AI Code SecurityAI Coding

AI generates roughly half of all committed code.

AI Code GenerationSoftware DevelopmentAI Coding

AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.

AI Code SecurityVulnerabilitiesAI Coding

Six of the 11 evaluated models had security pass rates between 50% and 53%.

AI Code SecurityModel EvaluationAI CodingLLMs

The best model available still failed nearly one in three security tasks.

AI Code SecurityModel EvaluationAI CodingLLMs