AI-Built Apps Compile Fine but Fail Security Checks Half the Time, Studies Show
A 2026 Veracode report analyzing code from over 100 AI models found that while AI-generated code achieves near-perfect syntax compliance, it passes security tests only 56% of the time on average when no security prompting or human review is involved. The findings are based on raw model outputs without guardrails, meaning the results reflect code that ships without any security oversight — a pattern common in small business app development. Two real-world cases illustrate the risk: a 2025 scan of 1,645 projects on Lovable's showcase found roughly 10% exposed sensitive user data due to missing or misconfigured database security rules. In Supabase-backed apps, the vulnerability stems not from a public API key — which is by design — but from absent Row Level Security policies that should restrict what data any given user can access. The core concern is not that AI code is inherently insecure, but that apps built quickly with AI assistants and never reviewed by security professionals are quietly going live with exploitable gaps.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in