1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/generative-ai-in-application-security-report-from-checkmarx/
8/12/2024 7:40:49 AM
Generative AI in Application Security report from Checkmarx
Generative AI,Application Security,Report,Checkmarx
/Generative-AI-in-Application-Security-report-from-Checkmarx-App-Developer-Magazine_b5qav5di.jpg
App Developer Magazine
Generative AI in Application Security report from Checkmarx

Security

Generative AI in Application Security report from Checkmarx


Monday, August 12, 2024

Richard Harris Richard Harris

Checkmarx recently released its Generative AI in Application Security report. The study highlights the tension between leveraging AI's productivity benefits and establishing governance to mitigate risks. It reveals that only 29% of organizations have governance over AI tools, and 15% prohibit AI for code generation, despite widespread usage.

Checkmarx, the in-cloud-native application security provider, has published its Seven Steps to Safely Use Generative AI in Application Security report, which analyzes key concerns, usage patterns, and buying behaviors relating to the use of AI in enterprise application development. The global study exposed the tension between the need to empower both development and application security (AppSec) teams with the productivity benefits of AI tools and establish governance to mitigate emerging risks.

"Enterprise CISOs are grappling with the need to understand and manage new risks around generative AI without stifling innovation and becoming roadblocks within their organizations. GenAI can help time-pressured development teams scale to produce more code more quickly, but emerging problems such as AI hallucinations usher in a new era of risk that can be hard to quantify. Checkmarx has successfully foreseen the problems that can arise with AI-generated code and we’re proud to be delivering next-stage solutions within the Checkmarx One platform today," said Sandeep Johri, CEO at Checkmarx.

Highlights of the Generative AI in Application Security report from Checkmarx include these findings showing the difficulty of establishing and enforcing governance

  • Only 29% of organizations have established any form of governance
  • 15% of respondents have explicitly prohibited the use of AI tools for code generation within their organizations
  • 99% report that AI code-generation tools are being used regardless of prohibitions
  • 70% say there is no centralized strategy for generative AI, with purchasing decisions made on an ad hoc basis by individual departments
  • 60% are worried about GenAI attacks such as AI hallucinations 
  • 80% are worried about security threats stemming from developers using AI
     
Only 29 percent of organizations have established any type of governance on the use of GenAI tools

Only 29% of organizations have established any type of governance on the use of GenAI tools in their organizations

Many CISOs are seeking to build the right level and types of governance in order to permit their application development teams to use AI coding tools. Given its ease of adoption, flexibility and utility, security leaders clearly understand its potential for helping to speed and scale application development in a time-pressured business environment.

However, generative AI is currently unable to follow secure coding practices or to produce truly secure code, which motivates some security teams to consider AI-driven security tools to help manage the proliferation of development teams’ AI-generated code. The Checkmarx study found that:

  • 47% of respondents indicated interest in allowing AI to make unsupervised changes to code
  • 6% said that they wouldn’t trust AI to be involved in security actions within their vendor tools
     

"The responses of these global CISOs expose the reality that developers are using AI for application development even though it can’t reliably create secure code, which means that security teams are being hit with a flood of new, vulnerable code to manage. This illustrates the need for security teams to have their own productivity tools to manage, correlate and help them prioritize vulnerabilities, as Checkmarx One is designed to help them do," said Kobi Tzruya, Chief Product Officer at Checkmarx.

Methodology

In early 2024 Checkmarx commissioned a global research firm to conduct a survey of 900 CISOs and application security professionals in companies in North America, Europe and Asia-Pacific with annual revenue of $750 million or more.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026




APAC 5G expansion to fuel 347B mobile market by 2030
APAC 5G expansion to fuel 347B mobile market by 2030 Tuesday, April 21, 2026


How AI is causing app litter everywhere
How AI is causing app litter everywhere Tuesday, April 21, 2026


The App Economy Is Thriving
The App Economy Is Thriving Monday, April 20, 2026


NIKKE 3.5 anniversary update livestream coming soon
NIKKE 3.5 anniversary update livestream coming soon Friday, April 17, 2026


New AI tool targets early dementia detection
New AI tool targets early dementia detection Thursday, April 16, 2026


Jentic launch gives AI agents api access
Jentic launch gives AI agents api access Wednesday, April 15, 2026


Experts warn ai-generated health content risks misinterpretation without human oversight
Experts warn ai-generated health content risks misinterpretation without human oversight Wednesday, April 15, 2026


Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines
Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines Tuesday, April 14, 2026


AccuWeather Launches ChatGPT Integration for Live Weather Updates
AccuWeather Launches ChatGPT Integration for Live Weather Updates Tuesday, April 14, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>