AI Now Writes Most Code for 42% of Developers — But Security Oversight Is Falling Behind

Listen to this Post

Featured Image
The rise of AI in software development is reshaping codebases worldwide — but are developers keeping pace with the risks?

Artificial intelligence is now an integral part of modern software engineering. According to the newly released Cloudsmith 2025 Artifact Management Report, 42% of developers who incorporate AI into their workflows admit that over half of their current codebase is AI-generated. While this signals a dramatic leap in productivity and automation, it also exposes a worrying trend: developers are leaning into AI-generated code without adequate safeguards.

The report, based on surveys and usage metrics, paints a picture of a rapidly evolving industry grappling with trust, oversight, and emerging threats. Although AI tools have undeniably enhanced development speed and scalability, only 67% of developers review AI-written code before deploying it, and just 34% use tools designed to enforce security policies on AI-generated artifacts. A small but risky 17% of developers reported using no AI-specific controls at all.

One of the most alarming revelations relates to the exploit technique known as “slopsquatting” — where attackers weaponize hallucinated package names suggested by AI coding assistants. This form of cyberattack is gaining traction and could easily bypass detection in codebases lacking rigorous review processes.

Even as 86% of developers report increased reliance on AI-influenced packages or dependencies, only 29% feel “very confident” in detecting vulnerabilities, especially within open-source libraries, which remain a primary source for AI-generated recommendations.

Cloudsmith CEO Glenn Weinstein emphasized the delicate balance: “AI tools have had a huge impact on developer productivity, which is great. But with potentially less human scrutiny on generated code, it’s more important than ever to ensure the right automated controls are in place for the software supply chain.”

The report doesn’t just focus on risks. It dives deep into how developers determine the trustworthiness of open-source packages, track AI-driven velocity in CI/CD pipelines, and navigate tooling upgrades in environments where security is often deprioritized despite being a stated concern.

💡 What Undercode Say:

The Cloudsmith report underscores a technological shift — not just in how software is written, but in how we conceptualize trust and security in the software supply chain. While the statistic of 42% AI-generated code is impressive, it also rings alarm bells.

AI is not inherently secure or insecure — it’s only as safe as the environment in which it’s deployed. And right now, many dev teams are moving too fast without watching their blind spots.

The troubling part? One in five developers say they “completely trust” AI-generated code. In the cybersecurity world, blind trust is a weakness, not a virtue. AI is a tool — powerful but fallible. Its outputs are vulnerable to subtle manipulations, data poisoning, and hallucinated suggestions that can turn into vectors for exploitation.

Consider slopsquatting: this isn’t theoretical anymore. Attackers are leveraging the very tools meant to accelerate development to insert malicious dependencies via plausible-looking but fake packages. If code review isn’t airtight — or worse, if it’s absent — these threats can go live unnoticed.

The lack of dedicated tools is another gap. Only a third of developers use enforcement tools for AI-generated artifacts. With attack surfaces expanding through AI-created scripts, packages, and configs, enforcement should be a default — not an optional layer.

On the flip side, developer velocity has skyrocketed. AI agents and assistants have dramatically slashed coding hours, boosted prototyping, and allowed teams to scale faster. But productivity gains shouldn’t come at the cost of introducing silent security debt.

Tooling upgrades stall not because of technical constraints but due to organizational inertia. Companies often pay lip service to security but treat it as a backburner issue — especially when short-term delivery metrics rule. That has to change. With AI in the driver’s seat, human oversight must evolve in lockstep — from policy enforcement and curated artifact repositories to robust automated scans.

The report should serve as a wake-up call: AI is revolutionizing software development, but without intentional governance, it may also unravel the very fabric of software security.

🔍 Fact Checker Results

✅ 42% of AI-using developers confirmed over half their code is AI-generated
✅ Only 67% of developers review AI-generated code before deployment
✅ “Slopsquatting” is a verified emerging exploit targeting AI-assisted development

📊 Prediction: AI Oversight Will Become the Next DevOps Battleground

Within the next 12–18 months, organizations will shift from celebrating AI-generated productivity to scrutinizing AI code trustworthiness. Expect the rise of AI security officers, code authenticity audits, and the mass adoption of AI artifact policy enforcement tools. Developers will be judged not only on output, but on how securely AI contributed to that output. The DevSecOps landscape is poised for its next major disruption — and AI governance will be at the center of it.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub:
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon