Webinar Description
Key Takeaways
- Examines findings from the 2026 GenAI Code Security Report, drawing on nearly four years of security data
- Addresses the persistent 56% security pass rate for AI-generated code despite improvements in generation accuracy
- Covers vulnerability classes, verification strategies, and release-gate controls for AI-authored code
- Designed for security leaders, AppSec professionals, developers, and risk managers in enterprise and regulated industries
- Focuses on practical guidance for policy development, risk prioritisation, and remediation acceleration
Introduction
Veracode is hosting a live webinar examining the security implications of AI-generated code, presenting findings from the 2026 GenAI Code Security Report. The session targets security leaders, application security professionals, and development teams grappling with the operational realities of integrating generative AI into software delivery pipelines. As organisations accelerate their adoption of AI-assisted development tools, the gap between code generation capability and code security performance has become a pressing concern for enterprise risk management.
The timing reflects a broader industry inflection point. While AI coding assistants have matured significantly in their ability to produce functional code, security outcomes have not kept pace. The report’s central finding—a 56% security pass rate for AI-generated code—underscores the need for organisations to reconsider how they verify, release, and maintain accountability for code that originates from machine learning models rather than human developers.
About This Event
The webinar translates nearly four years of accumulated security data into actionable guidance for software trust and release decisions. Veracode leaders will present analysis covering more than 100 AI models evaluated since 2023, offering a longitudinal perspective on how security performance has evolved alongside rapid advances in code generation technology. The session includes expert presentations followed by a question-and-answer segment, structured for both executive and technical audiences.
Security Performance and Vulnerability Patterns in AI-Generated Code
A central theme of the webinar is the disconnect between generation accuracy and security outcomes. AI models have become increasingly proficient at producing syntactically correct, functional code, yet the security pass rate remains stubbornly low. This creates a risk model challenge for organisations: code that compiles and runs correctly may still harbour vulnerabilities that traditional development workflows would catch through human review or established testing protocols.
The session will examine specific vulnerability classes that appear frequently in AI-generated code and discuss verification strategies that operate independently of the models themselves. This distinction matters because relying on AI tools to self-assess their security output introduces circular dependencies that undermine assurance. Verification, the webinar argues, must live outside the model.
Release Controls and Accountability Frameworks
Beyond vulnerability detection, the webinar addresses the governance and operational dimensions of AI-assisted development. Traditional release-gate controls were designed around human-authored code with established review processes. AI-generated code introduces new questions about accountability, auditability, and the appropriate level of scrutiny before production deployment.
The discussion will cover policy development for AI-authored code, risk prioritisation frameworks, and strategies for strengthening release-gate controls. For organisations in regulated industries—financial services, healthcare, government, retail, and energy—these considerations intersect with compliance obligations and audit requirements that demand clear chains of responsibility.
Accelerating Remediation and Risk Visibility
The webinar also addresses the remediation side of the equation. When vulnerabilities are identified in AI-generated code, organisations need efficient pathways to resolution that do not bottleneck development velocity. The session will explore approaches to accelerating remediation while maintaining risk visibility across the software delivery lifecycle. This includes integration considerations for static application security testing, dynamic application security testing, software composition analysis, and container security within AI-augmented development environments.
Who Should Attend
The webinar is designed for security leaders including CISOs and heads of application security, as well as developers, engineering managers, and security teams responsible for software delivery. Risk managers and compliance professionals in regulated industries will find the policy and governance discussion particularly relevant. Organisations that are scaling AI-assisted development or evaluating its adoption will benefit from the practical frameworks presented.
Industry Context
The application security landscape has shifted considerably as AI coding tools have moved from experimental novelty to mainstream adoption. This transition has outpaced the development of corresponding security practices, creating a gap that the webinar seeks to address. The framing positions the challenge not as a developer tooling issue but as a verification, release-control, and accountability concern that requires organisational attention beyond individual engineering teams.

