While 95% of surveyed organizations reported using AI tools in software development, only 24% have adopted comprehensive strategies to secure AI-generated code
BURLINGTON, Mass., Dec. 17, 2025 /PRNewswire/ -- Black Duck®, the leader in AI-powered application security, today announced the release of a new report, "Navigating Software Supply Chain Risk in a Rapid-Release World." The findings uncover a discrepancy between AI adoption and unprotected code, resulting in organizations having a widening risk gap.
The study, conducted by UserEvidence, is based on a survey of 540 software security leaders and practitioners. The report highlights a critical disconnect: while 95% of organizations are leveraging AI tools for software development, a mere 24% are implementing comprehensive intellectual property, license, security, and quality evaluations for AI-generated code. This oversight exposes the software supply chain to potentially severe and unaddressed risks.
Key Findings from the Report Include:
"We're in a new era of rapid software innovation, fueled by AI, but these findings reveal a critical challenge: security isn't keeping pace," said Jason Schmitt, CEO at Black Duck. "It's imperative that organizations prioritize robust security frameworks, with a sharp focus on AI-generated code and meticulous dependency management, to build truly resilient software supply chains."
The report emphasizes that a resilient software supply chain extends beyond mere compliance, enabling organizations to proactively address vulnerabilities, minimize downtime, prevent data breaches, and ultimately improve developer productivity and increase development velocity.
For more information, download your copy of the "Navigating Software Supply Chain Risk in a Rapid-Release World" report and read our blog post.
About Black Duck
Black Duck® meets the board-level risks of modern software with True Scale Application Security, ensuring uncompromised trust in software for the regulated, AI-powered world. Only Black Duck solutions free organizations from tradeoffs between speed, accuracy, and compliance at scale while eliminating security, regulatory, and licensing risks. Whether in the cloud or on premises, Black Duck is the only choice for securing mission-critical software everywhere code happens. With Black Duck, security leaders can make smarter decisions and unleash business innovation with confidence. Learn more at www.blackduck.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/black-duck-report-reveals-software-supply-chains-vulnerable-as-ai-adoption-outpaces-security-302644341.html
SOURCE Black Duck Software