It seems today that adapting to – and embracing – AI in AppSec is no longer optional. It’s true that AI is no longer a futuristic fantasy. It’s a vibrant reality shaking up every aspect of development and cybersecurity, but there is a tempest coming with both promise and peril: AI-generated code. 

Those fancy new generative AI tools your developers have fallen head-over-heels for are rapidly becoming indispensable for productivity, but let’s get real: They’re also becoming an increasingly juicy target for attackers.

Let’s get back to the question at hand, though. If you ask me, then the answer is AI won’t, and can’t, replace expert level engineers and analysts anytime soon, but that doesn’t mean it isn’t already leveling them up. Let’s dive into what that means and how we can secure the entire AI-driven development lifecycle.

AI code: Friend or foe?

Here are the facts: Developers are embracing AI-generated code because it boosts productivity. These Large Language Models (LLMs) excel at writing impressive snippets of code, completing boilerplate tasks, refactoring and improving existing codebases, debugging and identifying errors, and making documentation slightly less soul-draining.

But there’s a catch: LLMs weren’t exactly schooled in secure coding best practices. That slick-looking code snippet? It might just be the cybersecurity equivalent of a beautiful yet structurally unsound bridge. It looks fantastic, but it could collapse spectacularly under attack. 

AI also reflects biases and mistakes inherent in training data (public repositories), potentially propagating outdated, inefficient, or insecure practices. It also has a potential to hallucinate – make things up, including even inventing non-existent libraries.  Unclear intellectual property and licensing risks stemming from code generation using proprietary or GPL-licensed open-source repositories also poses legal and licensing risks.

This may be AI 101, but developers can’t implicitly trust AI-generated code as sound and secure. That trust, without verification, is an open invitation to trouble. They need review, and human eyes are still non-negotiable.

Read the full blog here.

If you’re sold on the value of AI in AppSec and how it can enhance your team, check out Checkmarx AI Security.

Share
Share