2026 GenAI Code Security Report
Veracode's 2026 GenAI Code Security Report (July 2026; 11 new models tested on 80 coding tasks, benchmark) found that AI-generated code passed security tests 56% of the time on average, barely changed from 55% in its first report.
Key findings
- 01The average security pass rate across models was 56%, barely changed from 55% in the first report.Roughly 44% of code generation tasks introduced a known vulnerability, even though models produce syntactically correct code nearly 100% of the time.
- 02The best model in the Summer 2026 snapshot, GPT-5.5, passed 68% of security tasks; six of eleven models scored 50–53%.Model choice matters, but even the best model still fails nearly one in three security tasks.
- 03Coding-specialized models averaged 51% and general-purpose models 52%.Reasoning models averaged 56% versus 51% for non-reasoning models; model size made little difference.
- 04Pass rates ranged from 87% on cryptographic algorithms and 83% on SQL injection to 15% on cross-site scripting and 12% on log injection.Flaws that depend on how data moves through an application remain the hardest for models.
- 05Java had the lowest mean security pass rate at 30%.Java also showed the clearest improvement trend of any language, Veracode says.
By the numbers
What it means for you Draft
If your developers or contractors use AI coding tools, this benchmark suggests close to half of what those tools write could contain a known security flaw unless it is checked. For a $10–100M company, that argues for keeping code review and automated security scanning in place, not cutting them because AI made writing code faster. The source sells security scanning, so the conclusion suits its business, but the test results are specific and repeatable.
Do not assume newer or code-specific models write safer code; run security scanning on AI-generated code as you would on any other. Pay particular attention to input handling, where cross-site scripting and log injection pass rates were lowest.
Limitations
Medium trust.Repeatable benchmark with disclosed task count, but full methods are gated and Veracode sells code security products.
This is a lab benchmark on 80 tasks without security-specific prompting, so real results may differ with better prompts, context or review. The full report is gated, and Veracode sells the scanning and remediation tools it recommends.
About the publisher: Sells application security testing and AI code remediation products.
Veracode. "2026 GenAI Code Security Report." July 28, 2026. https://www.veracode.com/resources/analyst-reports/2026-genai-code-security-report/


