It still ships a security hole in nearly half of it, and that has not changed in a year. That is the headline finding of Veracode’s 2026 GenAI Code Security Report, which tested more than 100 models across four snapshots. AI now writes roughly half of all committed code. On security, they fail nearly 44% of the time, introducing a vulnerability from the OWASP Top 10. “Models may be almost syntactically perfect, but they are still failing on nearly half of all tasks where security is needed,” said Chris Wysopal, Veracode’s co-founder and chief security evangelist.