AI-GENERATED code typically introduces an average of 15 vulnerabilities per codebase, largely influenced by the choice of development framework rather than the AI model itself. The AI Trust Index, created by Secure Code Warrior with RMIT University, assessed 1,760 codebases from 16 AI models and found varying risk levels. Notably, models from Anthropic performed better than those from OpenAI.
Organizations are advised to understand framework risks and focus training on critical vulnerabilities such as sensitive data leaks and cross-site scripting. The study emphasizes that careful model and framework pairing can significantly enhance coding security.