Survey: AI impact on security
Services
Industries
AI<br>Startups<br>Media<br>Education<br>Healthcare<br>Security
Technology
Company
About<br>Blog & Videos<br>Contact
Get in touch
Back
Survey: AI impact on security
Denis Stebunov
July 21, 2026
Estimated 3 minutes read
Follow us:
In June 2026, with the support of the amazing CTO Craft<br>and Rands Leadership Slack<br>communities, we surveyed engineering leaders from companies of all sizes to<br>understand how they use AI and how it impacts security within their teams.
Contents
Audience
Everyone writes production code with AI
Security and quality are the biggest concerns
The top mitigation tools are code reviews and security scanners
Conclusion
Audience
We conducted the survey with dozens of engineering leaders from companies of<br>all sizes, primarily across North America and Europe:
Most companies launched their products before the rise of AI coding, but there<br>are some newcomers, too:
Most of the products these companies are building handle sensitive data and<br>have either already achieved or plan to pursue compliance with security and<br>privacy standards:
Large companies tend to have a CISO and/or a dedicated security team, whereas<br>in smaller ones, security usually falls to the CTO or the software engineers:
Only about a third of respondents said they currently have junior positions<br>on the team:
Everyone writes production code with AI
Every respondent, without exception, said they use AI to write production code.<br>This appears to be the most widespread application of AI in software<br>development, ahead of all others:
The distribution of AI-generated code in production is fairly even, ranging<br>from under 25% all the way up to 100%:
The survey also included the option "0% (no AI-generated code in production),"<br>but no one selected it.
Security and quality are the biggest concerns
Most respondents think AI usage may represent an additional risk:
Surprisingly, cost seems to be the least of the concerns. This may be because<br>we were asking engineering leaders; had we asked CEOs or CFOs, the results<br>might have looked different:
Engineering folks are mostly concerned about security, code quality, and losing<br>understanding of the codebase. Here are some citations:
“Fast to write but raises tech debt and security issues or people lack<br>understanding of the designs"
“I've found that coding agents can easily overlook basic security needs,<br>whether configuring infra or using unsafe coding practices.”
“Decreased human attention to the critical pieces of software we're shipping<br>to production. Unintended consequences of AI-written code, especially ones<br>that accidentally degrade UX and expose new security flaws.”
“First and foremost is brain rot - forgetting how to do things (from simple<br>to complex). Next is reshaping expectations & trust - pushing a lot of code<br>with low trust is a very different dynamic than pushing some code with high<br>trust.”
“Over-engineering, as AI makes it easier: before the cost was implementation,<br>and now it is less of a burden”
“Losing manual coding skills, less thoroughly reviewed code, lower code<br>quality, broken devs learning process”
Most engineering leaders think their production code may contain<br>vulnerabilities:
42% of respondents said they experienced a security incident:
18% of respondents reported experiencing a supply chain attack, roughly half<br>of them within the past six months:
The top mitigation tools are code reviews and security scanners
So far, there seems to be no substitute for human code review. Although some<br>people mentioned AI code reviews, these were usually brought up as a complement<br>to human review rather than a replacement for it.
97% of respondents review AI-generated code the same as human-written code or<br>more strictly:
Conclusion
Two findings stood out to us.
First, everyone is using AI to write production code. That may not sound<br>remarkable at first, until you realize there were no exceptions. 100% of the<br>respondents have at least some AI-written code running in production.
Second, contrary to many headlines, cost doesn’t appear to be a problem<br>yet. Engineering leaders are primarily focused on security and code quality,<br>with only a tiny fraction citing cost as a concern.
We uncover software engineering
Get more stories like this in your inbox
Subscribe
Thank you! Your email has been subscribed.
Read previous
The best testing strategy
How do we balance unit, integration, and end-to-end tests? Should we follow Test Pyramid, Testing Trophy, or something else?
Services
Industries:
AI<br>Startups<br>Media<br>Education<br>Healthcare<br>Security
Technology
Company:
About<br>Blog & Videos<br>Contact