Code written with AI assistance needs the same audit as any other code, with extra attention where current models are measurably weak: authorization, input validation and anything that depends on the application’s own rules.
In Veracode’s 2026 GenAI Code Security Report of July 28, 2026, the average security pass rate across the models tested was 56%, against 55% in its first report, and the highest-scoring model reached 68%. Models averaged 83% on SQL injection tasks and 15% on cross-site scripting. Tenzai built 15 apps with five coding agents and reported on June 25, 2026 that it found 69 vulnerabilities and that none of the 15 apps had proper protection against cross-site request forgery.
Both companies sell security products, and both used tasks chosen to be security-relevant, so these are not failure rates for all AI-written code. The practical reading is narrower. Generated code is usually tidy and plausibly named, which makes a missing permission check harder to notice by eye, so we test access rules directly. When an audit shows that an app needs more than a list of fixes, the follow-on work is described under vibe coding rescue.