Report by Veracode

2026 GenAI Code Security Report

12 FINDINGSPublished Jul 28, 2026
View Original Report →

Key Findings

Six of the 11 evaluated models had security pass rates between 50% and 53%.

AI Code SecurityModel EvaluationAI CodingLLMs

The best model available still failed nearly one in three security tasks.

AI Code SecurityModel EvaluationAI CodingLLMs

AI generates roughly half of all committed code.

AI Code GenerationSoftware DevelopmentAI Coding

Security pass rates by programming language range from Python at 63% down to Java at 30%.

AI Code SecurityAI Coding

AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.

AI Code SecurityVulnerabilitiesAI Coding

The average security pass rate for AI-generated code across tracked models was 56%.

AI Code SecurityApplication SecurityAI Coding

Coding-specialized models averaged a 51% security pass rate, compared with 52% for general-purpose models.

Model ArchitectureAI Code SecurityAI CodingLLMs

OpenAI’s GPT-5.5 achieved a 68% security pass rate.

LLMsAI Code Security

Models generate compilable code at a near-universal syntax pass rate of approximately 100%.

Code QualityAI Code GenerationAI Coding

By model size, large models average a 53% security pass rate, while medium and small models each average 51%.

AI Code SecurityAI Coding

Alibaba’s Qwen3.7-max recorded a 50% security pass rate, generating vulnerable code every other output in this test.

AI Code SecurityModel EvaluationAI Coding

Reasoning models average a 56% security pass rate versus 51% for non-reasoning models.

AI Code SecurityAI Coding