Skip to content

Security of Code Generated by AI

The security risks in AI-written code and how to review, test and govern it.

Editorial team 1 min read

AI coding assistants speed up development, but generated code can contain vulnerabilities.

Common Issues

  • Injection vulnerabilities in queries and commands.
  • Missing input validation and output encoding.
  • Hard-coded secrets and weak cryptography.
  • Insecure defaults and outdated patterns from training data.
  • Package hallucination: suggesting dependencies that don't exist — which attackers can then register with malicious code.

Why It Happens

Models learn from public code, which includes insecure examples, and they optimise for code that looks plausible and works, not necessarily code that's secure.

Controls

  • Review: treat AI-generated code like any contribution — review it, especially security-sensitive parts.
  • Automated scanning: static analysis, dependency scanning and secret detection in CI.
  • Verify dependencies: confirm packages exist, are reputable and are the intended ones.
  • Tests: including security tests for authentication, authorisation and input handling.
  • Guidance: give assistants project security conventions in their instructions.

Agents With Commit Access

Coding agents that commit or deploy need permissions, sandboxing and review gates.

Use AI for Security Too

AI can also help review code for vulnerabilities — as an addition to, not a replacement for, established tools.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025