Back to Insights Penetration Testing

Research by Black Duck found that 95% of organizations trust AI in software development. But what about supply chain risks? Click to find out

AI in Code: Immense Speed, But Also a Risk That Cannot Be Ignored
Those who don’t check AI-generated code are leaving the “organization’s doors” wide open
The revolution is already here: everyone is using AI, but almost no one is checking it. Recent studies (Black Duck) reveal a jarring picture: while 95% of organizations already use artificial intelligence (AI) tools to write code faster, only 24% of them actually check this code before it enters the system.
What does this mean in practice? That large portions of your software are being written by a machine, yet they undergo fewer controls than human-written code. We are in an era where technology is racing forward, but security is struggling to keep pace.
The Risk: “Black Holes” in Your Supply Chain
Dependencies, multiple models, automation, and development speed open a door to vulnerabilities
When we talk about a software “supply chain,” we refer to all the external code components that your application relies on. AI tends to use external code libraries and models that are not always transparent to us.
The result is a loss of control over external components:
• Lack of transparency: We don’t always know where the AI “brought” the solution from.
• “Hitchhiking” libraries: AI might introduce external components into the code that cannot be easily monitored.
• Difficulty in oversight: The pace of development is so fast that it is hard to stop and verify that every line of code meets security and licensing standards.
In simple terms: it is easier to release a new version to customers, but much harder to ensure it is secure.
2030: When Code Will Be Stronger Than the Human Ability to Check It
When automation is more powerful than people
Projections show that by 2030, nearly 95% of the world’s code will be generated by artificial intelligence. Even today in young startups, AI is responsible for most of the code being written.
The problem is that human programmers are no longer capable of manually reading and scanning these quantities. Therefore, we need a new method – “smart systems that check smart systems” – and full automation of testing processes.
Recommendations from IPV Security Information Security Experts:

AI code is “Foreign Code”: Treat everything written by AI as a third-party product. it requires testing, documentation, and re-approval.
Software Bill of Materials (SBOM) management: Demand a full breakdown of all software components (like an ingredient list on a food product). Organizations that do this are much better prepared to handle attacks.
Vulnerability remediation automation: Use tools capable of identifying and fixing vulnerabilities automatically and continuously.
Supplier transparency: Ensure your AI providers declare the sources of their code and data.

In Conclusion,
The problem is not the artificial intelligence – it is the pace of security that has not been adapted to it. Organizations that are wise enough to adopt smart control processes, meticulous documentation, and automation will not only survive the AI revolution but will be able to use it to grow safely.
For more information: AI-generated code leaves businesses open to supply chain risk | SC Media
 

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation