The gap between AI velocity and security

Nearly all development teams now rely on AI coding assistants, and the productivity gains are real. Yet most organizations are producing AI-generated code faster than they can review, secure, or govern it. The result: time saved in code creation is subsumed into greater efforts elsewhere in testing, review, and issue management phases, often negating benefits of AI-assisted development.

We partnered with third-party research firm UserEvidence to survey 831 software engineers and DevOps professionals. The findings reveal a clear inflection point: The question is no longer if you use AI coding assistants; it’s how well you manage the AI-generated code they produce and establish deliberate, automated mechanisms to scale subsequent stages across the pipeline.

What you need to know

0 %
Of developers credit AI coding assistants with productivity and velocity gains
0 hours
Saved per week on average by developers using AI coding assistants
0 %
Of respondents say additional security testing and remediation are the biggest bottlenecks
0 %
Of developers feel they’re more likely to see major efficiency gains with full AI governance in place

The State of AI-Powered Software Development highlights

See what our expert reveals about the report’s key insights and what they mean for your organization.

The complete AI-powered software development landscape

90%
of teams encounter issues with AI-generated code that create cascading work across the SDLC
Media-CTA-991px-5x4-State-of-AI-number1

Productivity gains are real but are offset by friction

AI coding assistants are making it faster and easier to generate code at scale, but they create a bigger bottleneck to manage and secure that code.

68%
of developers say a clear, automated system for tracking AI code is critical
Media-CTA-991px-5x4-State-of-AI-number2

Governance unlocks AI’s full potential

Structured AI governance lags behind developer demand for it, but those who have full governance in place are 55% more likely to see a major improvement in efficiency

64%
of teams are concerned about AI security risks
Media-CTA-991px-5x4-State-of-AI-number3

Security concerns scale with AI usage

Higher utilization of AI-generated code yields both greater productivity and risk exposure.

84%
of teams prefer to keep a human in the loop
Media-CTA-991px-5x4-State-of-AI-number4

AI-assisted development demands human oversight

Teams are ready to scale with AI-assisted security tooling, but they prefer to keep humans in the loop via pull requests or real-time IDE suggestions.

“The teams that understand how to operationalize AI will win. To fully realize these gains, organizations must focus on guardrails and alignment to standards that serve as the blueprint for faster operations and remediation workflows.”
The State of AI-Powered Software Development

Keep pace with AI-powered software development pipelines

Black Duck Signal

Powered by ContextAI™, Black Duck Signal™ delivers real-time security analysis with human-curated intelligence so that security teams can govern, manage, and validate AI-assisted code without disrupting developer velocity.

Black Duck Polaris Platform

Black Duck Polaris™ Platform is a no-compromise AppSec platform unifying SAST, SCA, and DAST scanning with intelligent prioritization to deliver security at the speed, scale, and ambition of AI-powered development.

Black Duck Assist

Black Duck Assist provides AI-powered fix guidance backed by the industry’s deepest open source KnowledgeBase, providing accurate insights, real-time fixes, and remediation guidance inside existing developer workflows.

FAQ

It’s an independent market research report produced by Black Duck in partnership with third-party research firm UserEvidence. In March 2026, we surveyed 831 software engineers and DevOps professionals to get a clear, data-driven picture of how AI coding assistants are reshaping development workflows — and where the real friction points lie. The result is a benchmarking resource that cuts through the hype and gives you the numbers your team actually needs to make informed decisions about AI adoption, governance, and security.