Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Sunday, 7 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

by Guru Writer
June 1, 2026
in Featured
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool
Share on FacebookShare on Twitter

The rapid adoption of AI coding assistants is creating a new governance challenge for enterprise security teams, according to research released by Salt Security, which found that nine in ten security leaders are concerned about the security risks associated with AI-generated code. The research, AI Coding Assistants and the New Security Challenge, surveyed 100 IT security leaders across the UK and US and highlights the growing tension between software development speed and security oversight.

According to the study, 67% of organisations now report widespread adoption of AI coding assistants across development teams, reflecting how deeply AI has become embedded in modern software engineering practices. However, governance frameworks have struggled to keep pace. While organisations increasingly rely on AI to accelerate development, 38% still depend primarily on manual reviews to assess AI-generated code, a process many security leaders believe is becoming unsustainable.

Among respondents, 29% identified insecure coding patterns as the biggest risk introduced by AI assistants, while 15% cited concerns about generated code failing to align with internal security policies.

The findings mirror wider industry concerns about the quality and security of machine-generated software. According to figures cited by Salt Security, AI coding assistants now generate nearly half of all code written on platforms such as GitHub, while independent research has found that a significant proportion of AI-generated code contains known vulnerabilities.

“AI coding assistants are fundamentally changing how software is built, but governance has not kept pace,” said Roey Eliyahu, CEO and co-founder of Salt Security.

“Most organisations recognise the risks, but many are still trying to manage AI-generated code using security processes designed for a pre-AI world. That approach does not scale. Security leaders need visibility, consistency and embedded governance across the AI-assisted development lifecycle before code volumes become unmanageable.”

The research also revealed that larger enterprises face greater operational complexity as AI adoption grows. Organisations with more than 500 employees were significantly more likely to report challenges around governance consistency, developer overreliance on AI-generated outputs and policy enforcement across distributed development teams.

The findings coincide with the launch of Salt Code, a new addition to the company’s Agentic Security Platform designed to enforce security policies directly within AI coding assistants such as Claude Code, GitHub Copilot, Cursor, Gemini CLI and Codex. Salt Code is designed to move security controls earlier in the software development lifecycle. Rather than relying solely on traditional security testing tools after code has been written, Salt Code applies organisational security policies during code generation itself.

At the heart of the platform is Salt’s Posture Governance Engine, which allows organisations to define security and compliance requirements once and enforce them consistently across code creation, deployment and runtime environments. The platform includes pre-built policy packs covering frameworks such as the OWASP API Top 10, MCP Security Top 10, LLM Security Top 10 and OpenAPI/Swagger compliance.

According to Salt Security, the approach is intended to address what it describes as “security drift”, or the gradual divergence between organisational policies and actual development practices that can occur as AI-generated code volumes increase.

“AI is writing code faster than organisations can govern it, whether that AI is Claude, Gemini, Copilot, or the next tool a developer downloads tomorrow,” Eliyahu said.

“For the first time, security policy travels with the code itself, from the first prompt through every stage of the pipeline and into runtime. Organisations no longer have to choose between the speed AI enables and the security their business requires.”

Industry analysts have argued that governance will become increasingly important as AI-generated code forms a growing share of enterprise software. Salt’s research suggests that organisations are already recognising the challenge, with security leaders expressing concerns that manual review processes are struggling to scale alongside AI-assisted development.

“I regularly point organisations toward Salt because the full Agentic Security Graph is genuinely differentiating. Salt Code is the piece that ties it together,” said Christopher M. Steffen, CISSP, CISA, CCZ, VP of Research, Information Security, Risk and Compliance Management, Enterprise Management Associates. “With code-level context layered onto runtime behaviour, Salt is building a multi-dimensional defence for agentic systems rather than another single-point tool. That is the direction this market needs to move.”

The company is encouraging organisations to focus on improving visibility into AI-generated code, reducing dependence on manual review, standardising secure development practices and treating AI coding assistants as part of the wider software supply chain.

As enterprises continue to embrace AI-assisted development, the findings suggest that the next phase of adoption may be defined less by productivity gains and more by how effectively organisations can govern and secure the code these systems produce.

ShareTweet
Previous Post

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Next Post

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
data-cloud-security

Building a Digital Fortress: Why Cyber Security Matters More Than Ever

June 5, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol