AI-generated code is shipping to production without security review. The tools that generate the code don’t audit it. The developers using the tools often lack the security knowledge to catch what the models miss. This is a growing blind spot in the software supply chain.



Well… some do.
Jokes aside, I don’t think this is an undiscussed topic, and ultimately, the solution is the same, project culture. We use AI vibing for rapid proof of concept development, but the actual developed product needs to be correctly developed. Project leaders need to insist that code is responsibly written and reviewed. AI doesn’t change that.