securityonline.info 8 Oct 2026, 11:50 UTC

Insignary’s new scanner uncovers hidden code and AI dependencies

Insignary’s new scanner uncovers hidden code and AI dependencies
CyberSIXT Evidence Panel Source marked as original reporting

INSIGNARY has announced the general availability of Clarity AIR, a new source-code scanning product designed to expose what actually runs in software, beyond what developers declare. The tool works at the snippet and source-code level, comparing code against Insignary’s fingerprint database of the open-source ecosystem. It can identify open-source components that are not reflected in a project’s manifest or SBOM, including code that has been modified, adapted, or regenerated by AI coding assistants.

It also provides a per-line classification of how much of a codebase was AI-written, with a confidence score to help security, engineering and legal teams treat AI-derived output as a separate risk category. Additionally, Clarity AIR inventories AI dependencies—the models, APIs and frameworks embedded in the product—producing an AI Bill of Materials alongside the traditional open-source SBOM.

Insignary emphasises human review for every match, with results exportable as audit-ready SBOMs and full reports. The release arrives amid a patchwork regulatory landscape in North America, where US guidance under Memorandum M-26-05 pushes agencies to independently verify vendor SBOMs and FDA device submissions remain under separate rules; Canada’s Critical Cyber Systems Protection Act (Bill C-8) is phasing in supply-chain obligations.

Clarity AIR sits alongside Insignary’s existing Clarity binary analysis platform and SBOM governance tool, aiming to provide comprehensive visibility from source code through binaries to lifecycle management. Availability is immediate via Insignary and partners, with trial licences and a demo available on the company site.

View full article

Article by CyberSIXT