
Securing AI Code When Development Outpaces Human Review
Artificial intelligence is enabling development teams to produce much more code in less time. Security teams, however, must still review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. If software output rises by 10 to 50 times, traditional security processes may struggle to keep pace. The problem is no longer limited to finding vulnerabilities. Organizations must prevent security work from becoming a development bottleneck or losing control of what gets shipped. Producing more code can also create more components, dependencies, findings, and fixes for security teams to manage. For years, application security followed a familiar cycle: developers wrote code, scanners identified problems, security teams prioritized them, and engineers fixed the most important issues. Running more scans alone does not solve the new challenge because it can simply create a larger backlog. The same powerful AI models that help developers write and understand software are also available to attackers. Security teams are therefore being squeezed by both faster software production and accelerating attacker capabilities. A webinar held with Chainguard experts, titled “The True Cost of Building at Machine Speed,” examines this challenge. It moves beyond the question of whether AI-generated code is secure and focuses on what happens when software creation grows faster than people can realistically review and remediate it. The session explores where traditional CVE-driven remediation may begin to break down at machine scale, what secure-by-default development should look like, and how controls can continue working as AI adoption grows. It also considers how AI expands the software attack surface and why stronger guardrails may be needed before code reaches production. Slowing developers down is not presented as the answer because companies are adopting AI to build faster. The proposed approach is to make security operate at the same speed, using controls designed for current software-development practices. Somali developers who incorporate AI into their work may encounter the same gap between the speed of code creation and the capacity for security review. Controls integrated into development can help keep security work aligned with the growing volume of code.
Read our sourcing and corrections policy



Be the first to comment on this story!