Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today.
Automation, AI agents or people? Sorting out who handles each security finding
Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today.
Help Net Security
Publisher
Oct 7, 2026 at 4:30 AM UTC · Updated il y a un jour · 4 min de lecture


The respondents are senior people, most of them at companies with 10,000 or more employees, and their worries center on what happens after a scanner flags something. Someone has to decide whether the flaw matters, find out who owns it, and get the fix through teams that run on different tools and release schedules. Each delay in that chain leaves a known flaw open longer. Verizon’s 2026 Data Breach Investigations Report puts the median time to fully resolve a critical vulnerability at 43 days.
AI is adding to the pile
The pressure comes from both directions. AI tools let developers write and change software faster, and AI-assisted scanning turns up more weaknesses. Forty percent of respondents picked the amount of AI-generated code waiting for human review as their significant software-security challenge. AI-generated code is not inherently insecure, but there is more of it than human reviewers can keep up with.
That 40% comes with a catch. Each respondent picked one answer from a short list, so the figure shows that AI code review beat the other options for those people. It says nothing about how the remaining 60% rate the problem.
Article Intelligence
Topics
Regulation Signal
in progressUpdated il y a 2 mois
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
