Enterprise applications are now exhibiting a 4.31-fold increase in critical and high-severity vulnerabilities compared to the period before the widespread adoption of AI in software development. This finding comes from a recent analysis by Sonatype, which examined four years of enterprise software development data. The study indicates that while the pace of application creation has accelerated nearly fivefold in the AI era, the median age of unresolved vulnerabilities has decreased by 59%, suggesting that organizations are addressing vulnerabilities more quickly.
Despite the faster remediation times, the overall volume of risk is growing. Sonatype's report links this trend directly to the increasing use of artificial intelligence in software development, which enables teams to produce applications at a significantly higher rate. However, this accelerated production introduces new risks faster than traditional security processes can effectively manage.
The firm emphasizes that the improvements in vulnerability remediation have not kept pace with the rapid growth in software creation. This imbalance creates pressure to identify and mitigate risks much earlier in the development lifecycle.
According to Sonatype, the current approach, which often relies on security reviews primarily after development is complete, is insufficient. Instead, organizations need to integrate security decisions into the software assembly process itself. This shift would ensure that better security choices are made at the moment software components are put together, whether by human developers or AI agents.
The report highlights that AI is fundamentally altering the dynamics of software development, leading to more software being built more quickly, but also introducing risk at an accelerated rate. The solution, therefore, is not to simply add more review steps at the end of the development cycle, but to embed security considerations into the initial stages of software creation.


