TechNewsReel
Live

AI-Generated Code Outpaces Security Controls, Forcing Platform Rethink

Experts at PlatformCon London warn that non-deterministic AI software requires a shift toward runtime shields and AI-BOMs to manage escalating risks.

TechNewsReel Newsroom · August 6, 2026

The rapid adoption of AI for software development has created a critical security gap that traditional defense systems cannot bridge. At a recent panel discussion at PlatformCon London, industry experts warned that the speed and scale of AI-generated code are outpacing the security controls designed to manage it.

Platform engineers and leaders at the event reported widespread use of AI to write code, yet a majority felt their current security infrastructure was inadequate. The challenge is compounded by the non-deterministic nature of AI output, which can introduce vulnerabilities at a volume that human security teams cannot manually audit. According to the EdgeScan Vulnerabilities Statistics Report, 2025 saw a record 48,185 CVEs published, with 20% classified as critical or high severity and a mean time to patch or resolve of 55 days.

The Rise of Shadow AI

This vulnerability gap is widening due to the emergence of "Shadow AI," where non-technical employees deploy their own AI agents and software without oversight, significantly expanding the enterprise attack surface. To counter this, the industry is expanding traditional Software Bills of Materials (SBOMs) into AI-BOMs. These specialized inventories track model weights, training datasets, and third-party APIs to prevent data poisoning and close supply chain gaps.

A Shift to Runtime Protection

Because AI can produce flawed code instantly, reactive patching is no longer a viable primary defense. Experts argue for a fundamental shift toward "runtime shields," often utilizing eBPF, to provide immediate protection before a formal patch can be applied. This move toward instantly patchable platforms aims to mitigate "n-day" threats that AI can exploit almost as soon as they are identified.

Liz Rice, chief open source officer at Isovalent, noted that models are unlikely to write absolutely secure code any more than humans do. She observed that in the current environment, "the threat landscape has really changed a lot because finding vulnerabilities is almost wasted work now."

The End of the Zero-Day

As AI accelerates both the creation of software and the discovery of its flaws, the traditional concept of the "zero-day" vulnerability is evaporating. Joe Baguley, CTO of EMEA at Broadcom, stated that "there is no such thing as a zero-day anymore," reflecting a landscape where vulnerabilities are identified and weaponized with unprecedented speed.

Moving forward, the industry must watch how AI-BOMs are standardized and whether runtime shielding becomes the default architecture for enterprise platforms. The goal is to move from a cycle of discovery and patching to a model of continuous, automated resilience.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.