The open-source AI problem isn’t what you think it is

How many security vulnerabilities does your open-source codebase have? I hope you’re sitting down, because the newly published 2026 Open Source Security and Risk Analysis report from Black Duck has some bad news for you.

To quote: “Mean open source vulnerabilities per codebase more than doubled year over year (+107%), reaching an average of 581 vulnerabilities per application.”

Say whaaaat? That’s the big number, the small one is less shocking: 87% of codebases contained at least one vulnerability.

Of course, “at least” is doing a lot of heavy lifting here, and duplicated dependencies will amplify the total exposure as well. None of which takes away from the undeniable fact that open-source vulnerabilities are surging at what Black Duck has called a historic rate.

So, what’s causing this? Could it be that codebase sizes have also surged upwards? Yeah, that would certainly add to the risk of more vulnerabilities creeping in, I reckon. “Open source component counts increased 30% year-over year,” the report stated, “and the number of files per codebase grew 74%.”

But, guess what? AI has to enter the blame equation as well. No great surprise there then.

The Black Duck analysis found that only 54% of organisations reviewed AI‑generated code for licensing risk, and a mere 24% conducted any kind of comprehensive IP, security and quality evaluation.

Open source’s AI security problem

“It’s remarkable that despite the widespread awareness of AI risks, the number of vulnerabilities per application actually doubled in a single year,” said Ram Varadarajan, CEO at Acalvio.

This, he added, suggests that “the speed of AI-generated code is not just outpacing human review, but it’s actively overwhelming traditional DevSecOps controls.”

Colour me shocked, I tell you.

“AI has fundamentally changed the economics of software development,” said Jason Schmitt, CEO at Black Duck, “and with it, the economics of software risk.”

Schmitt also warned that “the pace at which software is created now exceeds the pace at which most organisations can secure it”.

Think about that, then act accordingly. AI is often seen as a silver bullet for meeting coding development timeline constraints, but don’t fire it at your own foot.

I’ll leave the final word to Randolph Barr, Chief Information Security Officer at Cequence Security. “The growing gap between the speed of innovation and the maturity of governance is what I find most important,” Barr told TechFinitive.

“Security programs need to change from controlling things only sometimes to continuously governing things automatically so they can keep up with development that happens at the speed of a machine.”

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.