
Product Announcements — SamHouston (Veracode) asked a question.
Today Veracode releases the second annual benchmark of AI model security performance — and the findings tell a story that every developer, security team, and engineering leader should sit with for a moment.
The full report is available now at the link below. Dig into the model-by-model breakdowns, the vulnerability category data, and what the trend lines say about where this is all heading.
👉 2026 GenAI Code Security Report
Nearly 1 in 2 AI-generated code tasks still introduces a known vulnerability.
That's not a headline designed to alarm. It's the result of testing 100+ models across four programming languages and four vulnerability categories — with a methodology consistent enough to make the trend data genuinely reliable. The number hasn't moved much since 2023.
Here's where it gets interesting: bigger doesn't mean safer. Large, medium, and small models all cluster within the same narrow band — 51–53% security pass rates. Coding-specialized models? They average 51%. General-purpose models? 52%. The gap is essentially noise.
What has changed is scale. Organizations adopting AI tools are shipping dramatically more code — which means the failure rate stays flat while total vulnerability volume climbs. Teams aren't seeing fewer bugs. They're seeing more of them, faster.
The takeaway for any team evaluating AI tooling: swapping models won't solve the security problem. The fix lives in the workflow — in scanning the code that AI produces, at the speed AI produces it.
.png)