93% Have Been Breached by Vulnerable AI Code. 30% Still Ship It Anyway.


Seventy per cent of developers believe AI-generated code carries more vulnerabilities than the code they write themselves. Thirty per cent ship it into production anyway, knowingly. Ninety-three per cent of the same respondents report at least one breach traced back to a vulnerable application. Awareness of the risk and action on the risk are not the same thing. They rarely are, according to every major AI risk study published so far this year.

 

The Core Finding Repeats Across Every Study That Looks

The Purple Book Community’s State of AI Risk Management 2026 report, surveying more than 650 senior cybersecurity leaders across North America and Europe between December 2025 and February 2026, found 59 per cent of organisations acknowledging shadow AI within their own environment, despite 90 per cent claiming confidence in their AI visibility. Seventy-eight per cent are already piloting or deploying agentic AI systems, and 73 per cent say AI-assisted development is outpacing their security review cycles. Fifty-one per cent run 11 or more separate security scanning tools, and 46 per cent of teams spend significant time triaging vulnerabilities that turn out not to matter. Governance has not kept pace with adoption. It has fallen further behind with each new AI capability organisations switch on.

 

The Global Maturity Picture Is Worse Than Any Single Region’s

The World Economic Forum’s Advancing Responsible AI Innovation research, covering 1,500 organisations worldwide, found 81 per cent still sitting in the earliest two stages of responsible AI maturity. Regional breakdowns make that global figure look almost optimistic. In Asia-Pacific, only 1 per cent of organisations have fully operationalised responsible AI practices, a gap researchers describe as more pronounced than the global average. Separate research from Dataiku found 94 per cent of CEOs suspect employees are already using generative AI tools without authorisation, while 75 per cent of data leaders admit low trust in their own organisation’s AI agent deployments.

 

The Middle East Shows a Different Symptom of the Same Disease

Middle Eastern enterprises are not struggling with pilots. Multiple regional AI advisory reports this year describe successful proof-of-concept projects stalling the moment organisations attempt enterprise-wide rollout, blocked by exactly the governance gap the global data points to: no clear ownership of AI risk decisions, inconsistent access controls, and the added complexity of navigating different data protection and AI-specific regulations across Gulf jurisdictions simultaneously. The technology performs in the pilot. The governance structure needed to scale it safely usually does not exist yet.

 

What This Means for How Organisations Govern AI Risk

Every regional variant of this research points to the same structural gap rather than three unrelated problems. A risk committee should treat confidence surveys as a warning sign rather than reassurance, ask specifically what percentage of AI-generated code has been reviewed rather than whether a review process exists on paper, and confirm who owns AI risk decisions before the next agentic AI pilot moves toward production. The pattern holding across North America, Europe, Asia-Pacific and the Gulf is consistent enough to stop treating it as one company’s oversight and start treating it as this year’s defining governance failure.