Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 24 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

AI and Regulation Redefine Application Security, New Global Study Finds

by Guru Writer
February 4, 2026
in Editor's News, Featured
AI and Regulation Redefine Application Security, New Global Study Finds
Share on FacebookShare on Twitter

Artificial intelligence has overtaken all other forces shaping application security, according to a major new industry study that shows organisations racing to secure AI-generated code while responding to growing regulatory pressure.

The 16th edition of the Building Security In Maturity Model (BSIMM), released by Black Duck, analysed real-world software security practices across 111 organisations worldwide, covering more than 91,000 applications developed by 223,000 developers. It is the largest and longest-running study of its kind, offering a data-driven view of how application security programmes are evolving in 2026.

For the first time in BSIMM’s 16-year history, AI has emerged as the single most influential factor reshaping security priorities. Organisations are now grappling with a dual challenge: securing AI-powered development tools such as large language model (LLM) coding assistants, while defending against increasingly sophisticated AI-enabled attacks.

AI-generated code introduces new security risks

The report highlights growing concern that AI-generated code, while often appearing polished and production-ready, can conceal serious security flaws. As a result, organisations are introducing new controls specifically designed to manage AI-related risk.

BSIMM16 found a 12% increase in organisations using risk-ranking methods to determine where LLM-generated code can safely be deployed, alongside a 10% rise in teams applying custom security rules to automated code review tools to detect vulnerabilities unique to AI-generated code. There was also a 10% increase in the use of attack intelligence to track emerging AI-related threats.

Rather than relying on trust in AI tools, security teams are increasingly embedding automated checks and governance mechanisms into the software development lifecycle to compensate for the limitations of AI-assisted coding.

Regulation accelerates security investment

Alongside AI, government regulation is a powerful driver of change. New and emerging mandates, including the EU Cyber Resilience Act and U.S. federal software security requirements, are forcing organisations to strengthen software supply chain visibility and improve their ability to demonstrate compliance.

The study reports a near-30% increase in organisations producing software bills of materials (SBOMs) for deployed software, reflecting growing demands for transparency into software components. Automated verification of infrastructure security increased by more than 50%, while processes for responsible vulnerability disclosure grew by over 40%, indicating a shift toward more structured, auditable security operations.

These changes suggest that regulatory compliance is no longer treated as a checkbox exercise, but as a catalyst for long-term improvements in application security maturity.

Supply chain security moves centre stage

BSIMM16 also shows organisations expanding their focus beyond internally developed code to address risk across the wider software supply chain. Increased use of third-party components, open source software, and AI-assisted development has heightened the need for standardisation and visibility.

The report observed a more than 40% rise in organisations establishing standardised technology stacks, as well as continued growth in SBOM adoption, signalling that supply chain security is becoming a core element of application security programmes rather than a specialist concern.

Security training adapts to modern development

Traditional security training approaches are also evolving. Lengthy classroom-based courses are increasingly being replaced by just-in-time, role-specific guidance delivered directly within developer workflows.

BSIMM16 recorded a 29% increase in organisations providing security expertise via open collaboration channels, allowing developers to access immediate support when security questions arise. This shift reflects the realities of agile development environments, where short, targeted guidance is often more effective than formal training sessions.

Framework stability signals maturity

Notably, BSIMM16 introduces no changes to the framework structure for the first time since the model was created. While many individual security activities showed significant growth, none shifted sufficiently to warrant reclassification.

According to the report’s authors, this stability signals that application security as a discipline has reached a level of structural maturity, even as AI, regulation, and supply chain complexity continue to reshape how organisations implement security in practice.

As organisations navigate an increasingly AI-driven development landscape, BSIMM16 provides a snapshot of how leading security teams are adapting, offering a benchmark for others seeking to balance innovation, compliance, and risk management in modern software environments.

ShareTweet
Previous Post

OT attacks surge as threat actors embrace cloud and AI, warns Forescout

Next Post

Attackers Use Legitimate Forensic Driver to Disable Endpoint Security, Huntress Warns

Recent News

Quantum computing: The data security conundrum

Trump Sets Post-Quantum Security Deadlines as White House Warns of Advanced Cryptographic Threats

June 23, 2026

Experts Warn: Passwords Still Winning Despite Passwordless Push

June 23, 2026
How Do Online Gaming Sites Keep Players and Their Data Safe?

KnowBe4 awarded in the email security industry

June 23, 2026
NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

NHS cyber resilience deal signals shift toward specialist MSSPs, says Check Point

June 23, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol