Checkmarx unveils results from its latest security report

Checkmarx-unveils-results-from-its-latest-security-report

Checkmarx has released its latest research, revealing a significant gap between AI-assisted software development and secure coding practices.

According to Checkmarx, whilst nearly all developers now write code with AI, fewer than one in five secure it as they go, citing limited use of in-IDE (Integrated Development Environment) application security (AppSec) tools and challenges integrating security into existing CI/CD pipelines.

Research revelations

The company revealed that the research also found that CISOs face similar pressures from business leaders, with 95% reporting they feel compelled to suppress or delay compliance-related security issues when business deadlines are at risk.

These findings are detailed in the 2026 Future of Application Security Report, which draws on responses from 2,350 CISOs, AppSec managers and developers across organisations in 14 countries.

While 96% of developers acknowledged having AI tooling in their IDEs and nearly unanimously rated it as effective, only 18% said they apply security continuously as they write code. 

Checkmarx added that the data highlights the unsettling fact that companies with 81-100% AI-generated production code are nearly three times more likely to ship software with known security vulnerabilities than companies with 1-20% AI code production (47% vs. 14%). 

The deeper issue cuts across all usage levels with 75% of organisations knowingly deploy vulnerable code at some point, driven by deadlines, complexity and the hope that flaws will not be discovered. 

Exposure

New frontier AI models are simultaneously exposing new attack surfaces and reducing time to exploit. 

Checkmarx said that the 2026 Future of Application Security report highlights the best practices of leading organisations who embed hybrid security into every layer that pairs deterministic ground truth with AI-augmented reasoning; prioritises formal AI governance policies; and uses automation to turn remediation from manual bottlenecks into defensive strengths.

The data shows the widening gap between the organisations who evolve with the threat-scape and those who still hope flaws won’t be found by the latest AI model advances.   

Key findings

According to Checkmarx, the key findings of the research include: 

  • An ounce of prevention is worth a pound of code. More than 80% of developers do not apply AppSec continuously as code is written, instead catching issues at defined stages after the code already exists or worse, reactively once incidents surface. Flaws caught late are flaws that can be exploited
  • Orgs acknowledge the AI risk, but action is lagging. In a year, the amount of vulnerable code knowingly shipped decreased from 81% to 75%, while formal AI governance policies at companies increased from 18% to 22%. As exploit windows collapse from years to minutes, incremental change is simply not enough.
  • The maturity mirage is real. 93% of organisations acknowledged a recent breach tied to their own applications, even as 73% describe their security posture as “advanced” or “highly mature”. There is a distressing disconnect between security confidence and security reality.
  • Governance? What governance? The 78% of organisations who lack formal AI governance policies are leaving the door open for shadow AI tools to proliferate and for exploitation of the unchecked code they quietly produce

“AI alone cannot secure code”

Sandeep Johri, CEO of Checkmarx explained: “This report points to a massive disconnect between the security crisis that organisations are facing and the incremental steps that they are taking to address it.

“A completely new model is required.

“Just like the student cannot grade their own exam, AI alone cannot secure code – and, as the research shows, it adds risk.

“Organisations need security that combines deterministic precision with probabilistic reasoning to identify novel exploitable patterns, while closing the gap between finding a vulnerability and fixing it with better human-guided remediation,” Johri concluded.

Agentic Appsec Unleashed 2026

The findings from this report will be highlighted in the upcoming virtual summit Agentic AppSec Unleashed 2026, hosted by Checkmarx on 16 June 2026.

Security and engineering leaders from leading enterprises will join Checkmarx executives and industry thought leaders to discuss our collective growing challenges and identify solutions that are poised to make an impact. 

“Organisations must urgently prioritise three things”

Jonathan Rende, Chief Product Officer for Checkmarx stated: “We are fighting a battle on two fronts as frontier models accelerate vulnerability discovery across legacy and open-source code, while AI-generated code widens the attack surface in every pipeline.

“What was once considered manageable risk, now looks like surrender.

“Organisations must urgently prioritise three things: collapsing raw findings into actionable signal, embedding remediation into every workflow and maintaining visibility across every aspect of their software supply chain,” he added.  

“The problem isn’t resources”

Yigal Elstein, Chief Revenue Officer at Checkmarx commented: “Our research found that over half (52%) of European CISOs had increased budgets – the highest proportion of respondents by geographical region. 

“Yet, European respondents also reported the highest breach frequency, with 60% of organisations having reported three or more breaches over the 12 months.”

Elstein continued: “At the same time, Europe has the slowest remediation rate, as over one third (35%) of organisations fix fewer than half of identified vulnerabilities within 90 days. 

“What to make of this discrepancy? The problem isn’t resources, as a higher budget doesn’t automatically lead to better outcomes.

“The issue instead lies in how these resources are deployed.

“We would suggest in the AI era of development, organisations shouldn’t normalise risk but rather use the resources available to secure their code,” Elstein concluded.  

Report

According to the company, the Future of Application Security 2026 report was conducted by Censuswide on behalf of Checkmarx between 10-30 March 2026, surveying 2,350 CISOs, AppSec managers and developers across 14 countries.

All responses were confidential. 

Censuswide is a member of the Market Research Society and the British Polling Council and adheres to MRS Code of Conduct and ESOMAR principles.

The full report is available for free at https://checkmarx.com/foa-report/

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox