DerScanner urges security process overhaul as AI-generated code grows

Jul. 20, 2026
By AI, Created 12:59 UTC, Jul 20, 2026, AGP -

DerScanner says application security teams need to rethink scanning, dependency checks and code review as AI-generated code becomes a larger share of production software. The company cites new data showing higher vulnerability rates in AI-assisted code and a growing AI supply chain risk that extends beyond source code itself.

Why it matters: - AI-generated code is expanding faster than many security programs were built to handle. - DerScanner says security teams need more frequent scanning, stronger dependency controls and broader review standards to keep pace with the volume of code now being shipped. - The risk is not limited to source code. AI tools, agent frameworks and connected development systems add a new supply-chain layer that can introduce vulnerabilities.

What happened: - DerScanner, an application security testing platform for regulated industries, published an analysis on how application security processes should change as AI writes a larger share of production code. - The company pointed to multiple studies showing elevated vulnerability rates in AI-generated code. - In March 2026, Snyk reported that 48% of AI-generated code contained security vulnerabilities. - Veracode’s testing of more than 100 large language models across 80 coding tasks found a 45% vulnerability rate. - CodeRabbit’s production analysis found AI-assisted code contained 2.74 times more vulnerabilities than human-written code. - Industry estimates place AI-generated code at about 27% of production code, with new code estimates ranging from 41% to 46%.

The details: - The analysis argues the core problem is not that AI writes worse code per line. - Vulnerability density per 1,000 lines remains roughly stable, but AI is producing more code at a speed that existing AppSec workflows did not anticipate. - The average number of known vulnerabilities per codebase rose from 280 to 581 in one year, a 107% increase. - DerScanner says scanning must match code velocity, with static analysis on every commit, software composition analysis on every pull request and secret detection in pre-commit hooks. - Dependency scanning becomes more important because AI assistants aggressively pull in packages while doing little to verify authenticity. - Dependency growth is estimated at 20% to 30%. - AI-generated code should be reviewed under the same standards as outsourced code. - One survey found only about 10% of developers scan most of the AI code they ship, even as trust in AI output falls. - The analysis rejects the idea that traditional static analysis is becoming unnecessary because AI can review its own code. - Large language models are non-deterministic, so the same input can produce different judgments. - Deterministic taint analysis remains the basis for compliance evidence, build gates and approval workflows. - A broader AI supply chain now includes models, agent frameworks and MCP servers connected to developers’ IDEs. - An audit of about 4,000 AI agent skills found more than 1,400 packages with issues, including 534 critical findings. - Existing supply-chain defenses such as SBOMs, reachability analysis and typosquatting detection need to extend to AI components.

Between the lines: - DerScanner is making a broader argument that AI changes security operations more than security theory. - The message is that teams cannot rely on one-time scans or occasional reviews when code output is rising and AI dependencies are multiplying. - The emphasis on deterministic analysis suggests compliance teams will still need auditable controls, even if AI tools are used earlier in the development process.

What's next: - DerScanner is positioning its platform around that shift. - The company says it combines SAST, DAST, SCA and MAST in one platform. - DerScanner also adds typosquatting detection, MavenGate monitoring, starjacking analysis and binary analysis for compiled code. - Its AI agents, DerTriage and DerCodeFix, run inside customer infrastructure, including air-gapped environments. - DerScanner says its platform supports 43 languages, including JavaScript, Python, Java and C#, as well as legacy languages such as Delphi, ABAP, Scala and Pascal. - The company says its reporting maps to OWASP Top 10, CWE/SANS Top 25, PCI DSS, HIPAA, ISO 27001, GDPR, the EU Cyber Resilience Act, NIS2 and DORA.

The bottom line: - As AI increases code volume, DerScanner says security teams need to shift from periodic scanning to continuous, supply-chain-aware AppSec controls.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

European News Update

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

European News Update

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.