AI Is Writing Code That Will Break the Internet
Will a major publicly-disclosed security breach or outage be directly attributed to AI-generated code by end of 2027?
If your company deploys AI-generated code, you're running a security experiment whether you know it or not.
Your Prediction
Where do you think this lands?
Join others who've weighed in
Scenarios
Current value: 69% of developers found AI-introduced vulnerabilities. 1 in 5 had material business impact. No headline-grabbing incident yet.
S-curve position: Pre-incident — vulnerabilities are accumulating but no catastrophic event yet
No major incident (security scanning improves faster, AI code stays in non-critical paths)
1-2 significant incidents, at least one making mainstream news, by end 2027
Multiple major breaches by mid-2027 (vibe-coded apps in production, supply chain attack via AI-generated dependency)
How We'll Know
- What we measure
- Whether a major security breach, data leak, or service outage is publicly attributed primarily to AI-generated or AI-assisted code
- Confirmed if
- A publicly-disclosed security incident affecting 1M+ users or causing $100M+ in damages is attributed primarily to AI-generated code
- Refuted if
- No major incident is attributed to AI code through end 2027, despite widespread AI code deployment
- Data sources
- CVE database
- NIST National Vulnerability Database
- Major breach disclosure reports
- Veracode / Opsera annual security reports
- News coverage of AI-attributed incidents
Evidence Trail
Evidence For
- Mar 9, 2026
Veracode 2026: only 55% of AI code secure. BaxBench: best model (Claude Opus 4.5) secure only 56% of the time. Opsera (250K+ devs): 15-18% more vulnerabilities. Cortex.io: incident rate per PR up 23.5%, change failure rate +30%. 69% of developers found AI vulnerabilities, 1 in 5 had material business impact. Sonar: Opus 4.6 has 21% more issue density than Opus 4.5. 'Architecture by Autocomplete' producing unnecessary micro-abstractions and N+1 query bugs.→ Probability: 60%
- Mar 9, 2026
Vibe coding going mainstream — VibeKode conference in Munich (June 2026). Lovable ($300M), Vercel v0, Replit enabling non-programmers to ship full-stack apps. 57% of orgs using AI for multi-step engineering workflows. Claude Code authors 4% of all GitHub commits (~135K/day). AI-authored production code at 26.9% and growing. The attack surface is expanding faster than security tooling can keep up.→ Probability: 65%
Evidence Against
- Mar 9, 2026
Major platforms adding security scanning before deployment. AI security tools (BugBot, Snyk AI) improving. Companies may keep AI code out of critical paths. The 'major incident' threshold ($100M+ or 1M+ users) is high — many smaller incidents may happen without crossing it.
What Experts Say
Cortex.io (Engineering Benchmark Report 2026)
Engineering Intelligence Platform
“AI-heavy engineering teams experience 23.5% higher incident rates per pull request and approximately 30% higher change failure rates”