- New SCW AI Trust Index shows AI-generated coding risk is not random, it’s predictable by model and framework, giving security leaders the data to safely scale AI-assisted development
Secure Code Warrior (https://cts.businesswire.com/ct/CT?id=smartlink&url=http%3A%2F%2Fwww.securecodewarrior.com&esheet=54573743&newsitemid=20260721153118&lan=en-US&anchor=Secure+Code+Warrior&index=1&md5=2a026ba0439349c2ae6170c47a3d4fcb), a leader in AI software governance and developer security upskilling, today introduced the SCW AI Trust Index (https://www.securecodewarrior.com/product/ai-trust-index), a living benchmark for AI coding security that grows with every new model, helping organizations understand and govern the security risks introduced by AI-generated code. Built on a methodology created with RMIT University, Australia (https://www.rmit.edu.au/), then extended by Secure Code Warrior, the research presents comprehensive benchmarks on how often leading LLMs produce insecure code, with material implications for every enterprise scaling AI-assisted development.
Based on an evaluation of 1,760 complete codebases generated by sixteen frontier models from OpenAI, Anthropic, Google, Alibaba and others, the findings show AI-generated code carries an average of 15 confirmed vulnerabilities per codebase, 4.3 of which are considered “severe”.
As developers continue to delegate code generation to frontier LLMs, it is critical for security leaders to understand what security risks developers are inheriting, and whether those risks vary by model, by framework, or by the interaction of the two. The SCW AI Trust Index brings empirical measurement to AI-generated code security, offering a living benchmark that evolves as new models emerge, not a one-time snapshot.
Starting today, organizations can utilize the SCW AI Trust Index to understand and mitigate risk in AI-driven software development by:
· Comparing AI coding models using real-world security data
· Identifying recurring vulnerability patterns
· Quantifying AI-generated coding risk with empirical data
“Every AI model we tested leaves a predictable, repeatable pattern of security gaps and weaknesses,” said Pieter Danhieux, Secure Code Warrior Co-Founder & Chief Executive Officer. “Developers are also predictable in that they aren’t going to abandon their preferred model over a security score. The SCW AI Trust Index was purpose-built to help CISOs and security leaders manage the models already in use; there is no identified “winner”, but this data provides the crucial insights needed to truly manage AI tools safely, with consideration to those inherent security gaps, and allow the right guardrails and developer learning pathways to be brought to life in a modernized security program. AI-generated code needs the same scrutiny we’ve always given human-written code, and now we finally have the data to know exactly where to look.”
Secure Code Warrior’s research reveals that AI-generated code security risk is not random, it is measurable, predictable, and concentrated in consistent patterns across AI models, frameworks, and vulnerability types. Key findings include:
· AI-generated vulnerabilities follow predictable patterns—not random failures
- Across 1,760 AI-generated codebases, Secure Code Warrior identified 86 unique CWEs, with the most common weaknesses clustering around logging failures, injection vulnerabilities, insecure design, and broken access control. The single most prevalent CWE was CWE-532: Insertion of Sensitive Information into Log Files, with 8,543 true positives. These recurring patterns demonstrate that AI-generated security risk is measurable, repeatable, and can be anticipated.
· Every AI model has a distinct security fingerprint
- Across all evaluated frameworks, models consistently exhibited recurring vulnerability patterns rather than random failures. The SCW AI Trust Index shows each model produces a repeatable mix of OWASP vulnerability categories, enabling organizations to anticipate where security weaknesses are most likely to occur.
· No single AI model consistently produces the most secure code
- Model performance changes significantly depending on the framework being used. GPT-5.1 leads in Java Enterprise API, Claude Sonnet 4.5 leads in Java Spring, Claude Opus 4.8 leads in Python Django, GPT-5.5 leads in C# (.NET), and Claude Fable 5 leads in C. Security outcomes depend on both the model and the development context.
· Security outcomes are independent of model cost
- The research found no consistent relationship between API cost and secure coding performance. For example, GPT-5.1 achieved one of the highest Trust Index scores at $5.60 per run, while significantly more expensive models produced weaker security outcomes. Organizations should evaluate AI models on measurable security performance rather than price.
The SCW AI Trust Index extends Secure Code Warrior’s mission by helping organizations understand how AI-generated code behaves, identify where risk is introduced, and enable developers to produce more secure code from the outset. By combining AI visibility, governance, and adaptive developer learning, Secure Code Warrior helps organizations confidently scale AI-assisted software development without sacrificing security.
To view the full research findings, visit: https://www.securecodewarrior.com/product/ai-trust-index
About Secure Code Warrior
Secure Code Warrior is a leader in AI software governance and developer security upskilling, enabling enterprises to control AI-driven software development across the SDLC. Built on a decade of developer security expertise, it delivers AI visibility, policy enforcement, and targeted learning to prevent vulnerabilities and strengthen software quality before production.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260721153118/en/
언론연락처: Secure Code Warrior Andrea Brusig
이 뉴스는 기업·기관·단체가 뉴스와이어를 통해 배포한 보도자료입니다.
Based on an evaluation of 1,760 complete codebases generated by sixteen frontier models from OpenAI, Anthropic, Google, Alibaba and others, the findings show AI-generated code carries an average of 15 confirmed vulnerabilities per codebase, 4.3 of which are considered “severe”.
As developers continue to delegate code generation to frontier LLMs, it is critical for security leaders to understand what security risks developers are inheriting, and whether those risks vary by model, by framework, or by the interaction of the two. The SCW AI Trust Index brings empirical measurement to AI-generated code security, offering a living benchmark that evolves as new models emerge, not a one-time snapshot.
Starting today, organizations can utilize the SCW AI Trust Index to understand and mitigate risk in AI-driven software development by:
· Comparing AI coding models using real-world security data
· Identifying recurring vulnerability patterns
· Quantifying AI-generated coding risk with empirical data
“Every AI model we tested leaves a predictable, repeatable pattern of security gaps and weaknesses,” said Pieter Danhieux, Secure Code Warrior Co-Founder & Chief Executive Officer. “Developers are also predictable in that they aren’t going to abandon their preferred model over a security score. The SCW AI Trust Index was purpose-built to help CISOs and security leaders manage the models already in use; there is no identified “winner”, but this data provides the crucial insights needed to truly manage AI tools safely, with consideration to those inherent security gaps, and allow the right guardrails and developer learning pathways to be brought to life in a modernized security program. AI-generated code needs the same scrutiny we’ve always given human-written code, and now we finally have the data to know exactly where to look.”
Secure Code Warrior’s research reveals that AI-generated code security risk is not random, it is measurable, predictable, and concentrated in consistent patterns across AI models, frameworks, and vulnerability types. Key findings include:
· AI-generated vulnerabilities follow predictable patterns—not random failures
- Across 1,760 AI-generated codebases, Secure Code Warrior identified 86 unique CWEs, with the most common weaknesses clustering around logging failures, injection vulnerabilities, insecure design, and broken access control. The single most prevalent CWE was CWE-532: Insertion of Sensitive Information into Log Files, with 8,543 true positives. These recurring patterns demonstrate that AI-generated security risk is measurable, repeatable, and can be anticipated.
· Every AI model has a distinct security fingerprint
- Across all evaluated frameworks, models consistently exhibited recurring vulnerability patterns rather than random failures. The SCW AI Trust Index shows each model produces a repeatable mix of OWASP vulnerability categories, enabling organizations to anticipate where security weaknesses are most likely to occur.
· No single AI model consistently produces the most secure code
- Model performance changes significantly depending on the framework being used. GPT-5.1 leads in Java Enterprise API, Claude Sonnet 4.5 leads in Java Spring, Claude Opus 4.8 leads in Python Django, GPT-5.5 leads in C# (.NET), and Claude Fable 5 leads in C. Security outcomes depend on both the model and the development context.
· Security outcomes are independent of model cost
- The research found no consistent relationship between API cost and secure coding performance. For example, GPT-5.1 achieved one of the highest Trust Index scores at $5.60 per run, while significantly more expensive models produced weaker security outcomes. Organizations should evaluate AI models on measurable security performance rather than price.
The SCW AI Trust Index extends Secure Code Warrior’s mission by helping organizations understand how AI-generated code behaves, identify where risk is introduced, and enable developers to produce more secure code from the outset. By combining AI visibility, governance, and adaptive developer learning, Secure Code Warrior helps organizations confidently scale AI-assisted software development without sacrificing security.
To view the full research findings, visit: https://www.securecodewarrior.com/product/ai-trust-index
About Secure Code Warrior
Secure Code Warrior is a leader in AI software governance and developer security upskilling, enabling enterprises to control AI-driven software development across the SDLC. Built on a decade of developer security expertise, it delivers AI visibility, policy enforcement, and targeted learning to prevent vulnerabilities and strengthen software quality before production.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260721153118/en/
언론연락처: Secure Code Warrior Andrea Brusig
이 뉴스는 기업·기관·단체가 뉴스와이어를 통해 배포한 보도자료입니다.
ⓒ 주식회사 에이아이크리에이티브랩 & www.aifilmjournal.com 무단전재-재배포금지
BEST 뉴스
-
Esri to Debut the Power of Where Collection at 2026 Esri User Conference
Esri (https://www.esri.com/en-us/what-is-gis/overview), the global leader in location intelligence, will debut the Power of Where Collection (https://powerofwhere.com/?aduc=Public_Relations&aduca=2026-MUL-Esri_Press_Books&aduco=press-release&adum=Press_Release&adut=pow-series&... -
Statement on Terminating the Letter of Intent With AI Financial Corporation
Statement from Matthew Nicoletti, Chief Strategy Officer, Perpetuals.com (Nasdaq: PDC), on the proposed transaction with AI Financial Corporation. “Perpetuals has decided not to further pursue the acquisition of AI Financial Corporation’s subsidiary Alt5 Sigma Canada, Inc. and the earlier letter... -
디자인 툴 필요없다… 비즈뿌리오, 알림톡 전용 ‘이미지 메이커’ 출시
비즈뿌리오 ‘이미지 메이커’ 기능 출시 기업 메시징 서비스 비즈뿌리오를 운영하는 다우기술(대표 김윤덕)은 카카오톡 알림톡에 포함되는 이미지를 손쉽게 완성할 수 있는 ‘이미지 메이커’ 기능을 지난 1일 출시했다고 밝혔다. 최근 카카오톡 알림톡은 단순 텍스트 형태를 넘어 브랜드 로... -
MUUT, 신세계 강남점 입성… 롯데 잠실 이어 팝업 확대
신세계 강남 MUUT 팝업 전경 패션 아이웨어 브랜드 뭍(MUUT)이 7월 9일부터 22일까지 신세계백화점 강남점 5층 팝업 스테이지에서 팝업 스토어를 운영한다. 이번 팝업은 MUUT의 다양한 아이웨어 제품과 브랜드가 제안하는 스타일을 직접 경험할 수 있는 공간으로 꾸며졌다. 롯데월드몰 잠... -
글렌알라키 ‘15년 컬렉터스 에디션 PART I’으로 JPM 어워즈 금상 수상
글렌알라키 15년 컬렉터스 에디션 파트 1 프리미엄 주류 수입 유통사 메타베브코리아는 자사의 대표 싱글몰트 위스키 브랜드인 글렌알라키의 한정판 패키지 ‘글렌알라키 15년 컬렉터스 에디션 PART I’이 일본 마케팅 업계 최고 권위의 시상식인 ‘제54회 Japan Promotional Marketing Award... -
소비자는 부담 덜고, 어가는 판로 확대… GS더프레시 ‘ESG 장어덮밥’ 출시
GS리테일이 운영하는 슈퍼마켓 GS더프레시는 국내산 민물장어 소비 촉진을 위해 ‘국내산 통한마리장어덮밥’을 출시한다고 14일 밝혔다. 이번 상품은 GS더프레시가 한국어촌어항공단, 해양수산부와 함께 추진하는 ‘Co:어촌 프로젝트’ 일환으로 기획됐다. Co:어촌 프로젝트는 기업의 상품 개발·유통 역량과 국내 어가의 ...
