AI-assisted code has 4.4 times more security flaws than human-written code, study finds

Aug. 27, 2026
By AI, Created 11:16 UTC, Aug 27, 2026, AGP -

State of Cyber, Symbiotic Security’s research lab, analyzed 1,967 public GitHub repositories and 1,072 vibe-coded apps from January to March 2026 and found AI-assisted code carried far more security flaws than human-written code. The findings raise the stakes for developers and security teams as AI speeds up software production faster than traditional review processes can keep pace.

Why it matters: - AI-assisted software is now producing more vulnerabilities, not just more code. - State of Cyber found a gap that affects both public repositories and production apps built with vibe-coding tools. - The study underscores a security problem for teams adopting AI faster than they can add safeguards. - The findings matter most for organizations that must balance speed, compliance, and secure development at the same time.

What happened: - State of Cyber released "AI vs Humans: Security at Scale," a research report published Aug. 27, 2026. - The lab analyzed 1,967 public GitHub repositories over three months. - Researchers also scanned 1,072 vibe-coded applications across five popular platforms. - The full audit ran through 10 independent security scanners. - The combined review identified 87,826 vulnerabilities across both datasets.

The details: - AI-assisted repositories averaged 42.3 vulnerabilities each. - Human-written repositories averaged 9.6 vulnerabilities each. - That means AI-assisted code had 4.4 times more vulnerabilities on average. - 70.5% of AI-assisted repositories had at least one security issue. - 50.4% of human-written repositories had at least one security issue. - The repository findings covered 104 different vulnerability types. - The vibe-coded app review found 98% of applications with at least one vulnerability. - 29% of those applications had a high or critical issue. - 16%, or about one in six, allowed an unknown user to delete or alter data without authentication. - The app audit found 6,185 vulnerabilities total. - That works out to 5.9 vulnerabilities per application on average. - The data collection ran from January to March 2026. - The researchers said the work used automated large-scale processing and followed responsible disclosure principles. - The lab said no data was exfiltrated, stored, or shared beyond what was needed to document and report each vulnerability. - The results are published on state-of-cyber.org.

Between the lines: - The core risk is not just that AI writes insecure code, but that it speeds insecure code into production faster than manual review can keep up. - Vibe coding lowers the barrier to building software, which also lowers the barrier to shipping insecure databases and applications. - State of Cyber argues the security function has to move earlier in the development process, while code is still being written. - Independent research cited in the release points to a broader pattern: roughly half of AI-generated code contains an exploitable flaw, and that rate has not improved much even as models have gotten better. - For European organizations, the timing is especially sensitive because AI Act, NIS2, and DORA all increase pressure to prove software governance while adopting AI quickly.

What's next: - Symbiotic Security said the findings will be a major topic at the Assises de la Cybersécurité in Monaco from Oct. 7-10, 2026. - The company will showcase real-time safeguards at the event. - Security teams interested in meetings on site can contact marketing@symbioticsec.ai or use the company’s website. - State of Cyber said its product, Symbiotic Code, detects and fixes vulnerabilities while code is being written, with any model. - The company said early customers have reduced AI-generated vulnerabilities by up to 93%.

The bottom line: - The study puts a hard number on a growing problem: AI speeds up software creation, but security controls have not kept pace.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Monaco Daily Record

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Monaco Daily Record

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.