Veracode · July 2026

2026 GenAI Code Security Report

Veracode's 2026 GenAI Code Security Report (July 2026; 11 new models tested on 80 coding tasks, benchmark) found that AI-generated code passed security tests 56% of the time on average, barely changed from 55% in its first report.

Read the original report ↗Cite2 min read · Summary updated
Security pass rate of AI-generated code by vulnerability type% of tasks passed
Cryptographic algorithms
87%
SQL injection
83%
Cross-site scripting
15%
Log injection
12%
Source: Veracode, 2026 GenAI Code Security Report, 2026.

Key findings

  1. 01
    The average security pass rate across models was 56%, barely changed from 55% in the first report.Roughly 44% of code generation tasks introduced a known vulnerability, even though models produce syntactically correct code nearly 100% of the time.
  2. 02
    The best model in the Summer 2026 snapshot, GPT-5.5, passed 68% of security tasks; six of eleven models scored 50–53%.Model choice matters, but even the best model still fails nearly one in three security tasks.
  3. 03
    Coding-specialized models averaged 51% and general-purpose models 52%.Reasoning models averaged 56% versus 51% for non-reasoning models; model size made little difference.
  4. 04
    Pass rates ranged from 87% on cryptographic algorithms and 83% on SQL injection to 15% on cross-site scripting and 12% on log injection.Flaws that depend on how data moves through an application remain the hardest for models.
  5. 05
    Java had the lowest mean security pass rate at 30%.Java also showed the clearest improvement trend of any language, Veracode says.

By the numbers

56%average security pass rate across models
68%best model's security pass rate (GPT-5.5)
12%pass rate on log injection tasks

What it means for you Draft

For executives at $10–100M companies

If your developers or contractors use AI coding tools, this benchmark suggests close to half of what those tools write could contain a known security flaw unless it is checked. For a $10–100M company, that argues for keeping code review and automated security scanning in place, not cutting them because AI made writing code faster. The source sells security scanning, so the conclusion suits its business, but the test results are specific and repeatable.

For practitioners

Do not assume newer or code-specific models write safer code; run security scanning on AI-generated code as you would on any other. Pay particular attention to input handling, where cross-site scripting and log injection pass rates were lowest.

Limitations

Medium trust.Repeatable benchmark with disclosed task count, but full methods are gated and Veracode sells code security products.

This is a lab benchmark on 80 tasks without security-specific prompting, so real results may differ with better prompts, context or review. The full report is gated, and Veracode sells the scanning and remediation tools it recommends.

About the publisher: Sells application security testing and AI code remediation products.

Cite the original

Veracode. "2026 GenAI Code Security Report." July 28, 2026. https://www.veracode.com/resources/analyst-reports/2026-genai-code-security-report/