Sembi Report Finds AI-Generated Code Spurs QA and Security Tool Challenges
A new industry‑wide survey by Sembi, involving almost 4,000 software engineers, QA professionals and security experts, reveals that over half of the code in use today—about 53%—is AI‑generated or AI‑assisted. This shift is straining existing application security testing practices. While static application security testing (SAST) remains the most common method, only 9% of teams report fully integrated security toolchains, and false‑positive rates hover near 50%, eroding trust in the tools. Data breaches, cloud misconfigurations and AI‑specific threats top the security concerns for 2026.
On the quality assurance side, the same report highlights a gap between rapid release cycles and testing capacity. Only roughly 26% of QA teams are meaningfully integrated with DevOps pipelines, leaving many to cope with higher testing demand driven by AI‑generated code. Although 57% of tests are automated, teams face staffing shortfalls—44.7% report being understaffed—with little expected head‑count growth. Integration with continuous‑integration/continuous‑deployment (CI/CD) environments emerges as the strongest differentiator between high‑ and low‑performing teams, offering faster releases and lower defect leakage.