Secure Code Warrior Research Reveals AI-Generated Code Introduces an Average of 15 Vulnerabilities Per Codebase
15:18 · July 21, 2026 · RSS APP - AI Primary Research

New SCW AI Trust Index shows AI-generated coding risk is not random, it’s predictable by model and framework, giving security leaders the data to safely scale AI-assisted development SYDNEY & BOSTON & LONDON–BUSINESS WIRE– Secure Code Warrior, a leader in AI software governance and developer security upskilling, today introduced the SCW AI Trust Index, a … Continued
Summary
Secure Code Warrior has introduced the SCW AI Trust Index, a living benchmark developed in collaboration with RMIT University to measure the security of code produced by frontier large language models. The index evaluates 1,760 complete codebases generated by sixteen models from providers including OpenAI, Anthropic, Google and Alibaba, tracking how often these systems introduce confirmed vulnerabilities during routine development tasks.
Across the evaluated codebases, the research records an average of 15 vulnerabilities per codebase, of which 4.3 are classified as severe. The study identifies 86 distinct Common Weakness Enumerations, with the most frequent being CWE-532 (insertion of sensitive information into log files), accounting for 8,543 confirmed instances. These weaknesses cluster around logging failures, injection flaws, insecure design choices and broken access control, forming repeatable patterns rather than isolated errors.
Each model exhibits a distinct security profile that shifts according to the target framework. Performance rankings change across Java Enterprise API, Spring, Python Django, .NET and C environments, with no single model dominating all contexts. The data also show no consistent link between API pricing and security outcomes; higher-cost models do not reliably produce fewer vulnerabilities.
The findings indicate that AI-generated code security risk can be anticipated by model and framework combination, allowing security teams to apply targeted controls instead of relying on generic model selection or cost-based assumptions. The index is designed to be updated as new models appear, providing ongoing empirical data for governance decisions.
Why it matters
This research provides crucial empirical data on the security risks of AI-assisted development, directly supporting the Dutch AI market's focus on secure, ethical, and transparent AI deployment. It offers actionable insights for Dutch researchers and CISOs to benchmark LLMs and implement necessary guardrails in enterprise software development.








