Secure Code Warrior has introduced the SCW AI Trust Index, a new benchmark designed to help enterprises evaluate and govern the security risks associated with AI-generated code. Based on research conducted using thousands of AI-generated codebases from leading large language models (LLMs), the index provides organizations with empirical insights into AI coding security, enabling more informed decisions as AI-assisted software development becomes increasingly widespread.
Secure Code Warrior announced the launch of the SCW AI Trust Index, a living benchmark that measures the security performance of AI-generated code across leading large language models. Developed using a methodology created in collaboration with RMIT University in Australia and further expanded by Secure Code Warrior, the benchmark is designed to evolve alongside emerging AI models rather than serve as a one-time assessment.
The research evaluated 1,760 complete codebases generated by 16 frontier AI models from providers including OpenAI, Anthropic, Google, Alibaba, and others. The findings reveal that AI-generated code contains an average of 15 confirmed vulnerabilities per codebase, with 4.3 classified as severe, highlighting the growing importance of AI governance within enterprise software development.
The SCW AI Trust Index provides organizations with measurable insights into how AI coding assistants introduce security vulnerabilities. Rather than producing random security issues, the research found that AI models consistently generate repeatable patterns of vulnerabilities, allowing security teams to better anticipate and mitigate risks.
Organizations can use the benchmark to:
"Every AI model we tested leaves a predictable, repeatable pattern of security gaps and weaknesses," said Pieter Danhieux, Secure Code Warrior Co-Founder & Chief Executive Officer. "Developers are also predictable in that they aren't going to abandon their preferred model over a security score. The SCW AI Trust Index was purpose-built to help CISOs and security leaders manage the models already in use; there is no identified "winner", but this data provides the crucial insights needed to truly manage AI tools safely, with consideration to those inherent security gaps, and allow the right guardrails and developer learning pathways to be brought to life in a modernized security program. AI-generated code needs the same scrutiny we've always given human-written code, and now we finally have the data to know exactly where to look."
The research identified several trends that have significant implications for organizations adopting AI-assisted software development.
Across the analyzed codebases, Secure Code Warrior identified 86 Common Weakness Enumerations (CWEs). The most frequently occurring vulnerabilities involved logging failures, injection attacks, insecure design, and broken access control. The most common weakness was CWE-532: Insertion of Sensitive Information into Log Files, with 8,543 confirmed instances, demonstrating that AI security risks are measurable and predictable.
Rather than exhibiting random behavior, each evaluated AI model consistently generated its own recurring mix of OWASP vulnerability categories across different frameworks. These distinct security fingerprints allow organizations to better understand where specific models may introduce security weaknesses.
The study found that no single AI model consistently generated the most secure code across every programming framework. Performance varied depending on the development environment, with different models performing best for Java Enterprise API, Java Spring, Python Django, C# (.NET), and C development.
The research also concluded that API pricing is not an indicator of secure coding performance. Some lower-cost models achieved stronger security results than more expensive alternatives, suggesting organizations should prioritize measurable security performance rather than cost when selecting AI coding assistants.
The SCW AI Trust Index expands Secure Code Warrior's approach to AI software governance by helping organizations understand how AI-generated code behaves, identify recurring security risks, and strengthen developer security practices. By combining AI visibility, governance, policy enforcement, and developer education, the company aims to help enterprises scale AI-assisted software development while maintaining secure coding standards.
About Secure Code Warrior
Secure Code Warrior is a leader in AI software governance and developer security upskilling, enabling enterprises to control AI-driven software development across the SDLC. Built on a decade of developer security expertise, it delivers AI visibility, policy enforcement, and targeted learning to prevent vulnerabilities and strengthen software quality before production.