Developers now report that about 42% of the code they commit is written or assisted by AI, most of what today's models produce ships with an exploitable flaw, and the time to fix one before it's exploited has collapsed toward zero. Regulators and cyber underwriters moved on it before most security teams did.
Veracode's March 2026 re-run found 45% of AI-generated samples still ship an OWASP Top-10 flaw, flat even as the models get better at writing code that works. BaxBench, which writes real exploits against generated backends, is starker still: roughly half of the code that passed its functional tests was still exploitable.
Regulators put the fix on the security leader's signature. Under NYDFS Part 500 a carrier's highest-ranking executive and CISO personally certify material compliance every year, and Part 500 requires timely, risk-prioritized remediation. EU DORA escalates missed patch deadlines under national penalty regimes reaching 5-10% of turnover. CISA BOD 26-04 cut the highest-risk clock to three calendar days.
The rules tightened on one clock. The attackers were already running a faster one.
Another scanner won't help. Only 18% of findings rated "critical" stay critical once runtime context is applied (Datadog 2026), and the average organization absorbed roughly 865,000 alerts in a single quarter. Most carriers surface far more genuine, ranked risk than they can act on.
If the constraint is fixing, that is the part to automate. Pixee runs two motions on one context graph, on the stack you already own.
It reads your existing scanners' output and clears the noise, so your team sees the findings that are actually exploitable in your code instead of the whole pile — up to 95% fewer false positives. For the real ones, it writes the fix as a reviewed pull request in your own coding style, not a generic AI patch. Your developers approve or reject it like any other PR, and they merge about three in four (a 78% merge rate, measured across production customer deployments). Deployed self-hosted it runs in your own environment, so source code never leaves, and it keeps a record of every decision — exactly what an examiner or underwriter asks to see.
Automated remediation is strongest on the shallow flaws AI is already reducing, and weakest on the privilege-escalation and design flaws it is multiplying. So Foresight moves earlier. It reviews the design before an agent writes the code, then checks that the shipped code kept the plan. As coding agents write more of the software, the specification becomes where security is won or lost. The cheapest vulnerability is the one you never introduce.
Together they move remediation from the financial sector's 276 days to fix half its flaws toward days, with a human reviewing every change before it merges.














No rip-and-replace. Pixee runs on the 12 scanners you already have natively, plus anything that speaks SARIF, self-hosted in your own environment.
AI-Written Code Is Outrunning Insurance Security Teams: An Industry Teardown. The primary sources behind every number above, plus a reading list for insurance security leaders. No form.
Download the PDF ↓The briefing security leaders actually read. CVEs, tooling shifts, and remediation trends — distilled into 5 minutes every week.
Join security leaders who start their week with AppSec Weekly. Free, 5 minutes, no fluff.
First briefing drops this week. Check your inbox.
Weekly only. No spam. Unsubscribe anytime.