Press Release Checkmarx Fusion: Hybrid Scanning Delivers the Most Complete Vulnerability Detection Available Read Now
Gartner® Checkmarx Named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security Get the Report
Outlook Report The Future of Application Security in the Era of AI Download Now
Webinar The AppSec Bottleneck Has Moved Downstream: Why visibility is no longer enough in the age of AI-generated code Watch Now
Latest Innovations
Checkmarx for Developers
Partners
Blog
Research

We Now Build Code Faster Than We Can Understand It: The New Risk of AI Speed

AI is generating code faster than teams can review it. Learn how hybrid SAST and Checkmarx Fusion help detect AI-era software security risks.

There’s an old story about an apprentice who enchants a broom to fetch water, then can’t stop it. He panics and hacks it in half, only to end up with two brooms working just as fast, then more, then a flood, because the process he set loose was never going to slow down just because he wanted to stop it. Software in 2026 has the same problem. It doesn’t need more automation. It needs something that can actually keep up with what’s already been set loose. 

Securing enterprise codebases was already challenging because most contain code written in multiple languages. AI assistants are now adding to that challenge by generating code in whichever language they determine is best for the task, whether or not your scanner can read it. TIOBE’s index now tracks more than fifty languages in active use – and they aren’t the languages you might expect. For example, Go and Haskell now rank alongside Python on some of today’s most visited sites. 

Those AI assistants write faster than people do, too. Microsoft Research clocked developers using GitHub Copilot at 55.8% faster on an identical task than developers without it. Checkmarx’s 2026 Future of Application Security survey names what that speed has done to the job: developers have moved from authoring code to editing it, supervising output instead of producing it.  

That combination – more code, written faster, across more languages – creates a security challenge most teams don’t understand and were not built to handle. This is where vulnerabilities live. 

The more production code AI generates, the more risk can slip through at scale. According to the same report, organizations where 81-100% of production code is AI-generated ship known vulnerabilities at 3.4x the rate of organizations where AI writes just 1-20%.  The issue is not just speed. AI-generated code can look correct while still carrying insecure patterns from the code it learned from, making vulnerabilities easier to miss and harder to trace. 

And, in addition, attackers are not waiting for security to catch up. Anthropic’s research on N-day exploits found that WannaCry took 59 days to weaponize after its 2017 patch, and that 16 of 25 historical vulnerabilities studied by Mandiant took a month or more to exploit. That timeline is already history. In the same research, Anthropic’s own model, Claude Mythos Preview, had a working Firefox exploit ready within an hour of Mozilla shipping the patch, 18 days before the patched browser itself even went out.  

The imbalance is clear: attackers can now move in hours, while defenders are still trying to understand code generated at AI speed, across more languages than ever. Closing that gap needs to start before the code ships. 

One Scan, Two Lenses 

Scanning code has always meant choosing a lens. A deterministic scanner looks through the lens of known rules, signatures, and patterns. It is consistent: run it twice on the same code, and you’ll get the same result. This repeatability is why auditors and compliance teams trust it. An AI-based scanner uses a different lens. It reasons through code more like a human reviewer, which helps it catch risks that do not match a known rule or signature. But that flexibility comes with less predictability: ask it the same question twice, and the answer might change. 

Neither one was ever going to be enough by itself. That is the compromise Checkmarx’s hybrid architecture refuses to make: depending on the language, either a deterministic, rules-based engine or an AI-based reasoning engine runs, and a Findings Analysis Engine (FAE) reconciles the output into one validated list. That pairing is Next-Gen SAST, built for known, N-day vulnerabilities at the highest fidelity a scanner reaches without going further. On its own, it reaches an F1 score of 0.64, up from 0.20 for basic query-based scanning, the standard approach used by traditional SAST solutions. 

One Step Further 

But known and N-day vulnerabilities are only part of the picture. The harder challenge is finding risks with no CVE, signature, or established pattern to match.  

That is where Checkmarx Fusion, currently in Early Access, adds another layer. Built on top of Checkmarx’s next generation hybrid SAST scanner, Checkmarx Fusion runs several frontier AI models, hunting for zero-day and unknown-pattern findings with no CVE or signature yet to match. Checkmarx reconciles that broader set of results back through the same rigorous validation process, producing one trusted output.  

Run together, Checkmarx SAST with Checkmarx Fusion achieves an F1 score of 0.74. The point is not to add AI just for the sake of it. The point is to give developers scan results that they can trust: precise enough to avoid false-positive noise, and broad enough to catch critical vulnerabilities that simpler scanners might miss.  

 Frontier AI models give Checkmarx Fusion a broader detection lens, surfacing complex or novel vulnerabilities that static rules and signatures alone would miss. And because AI models evolve rapidly, Checkmarx isn’t locked to any single one. The best model today may not be the best model tomorrow. So as models improve, Checkmarx swaps in whichever performs best – while the deterministic backbone, code context, and validation process remain fixed. 

Inside Checkmarx One 

A clean finding is not the same as a fixed one. Checkmarx Fusion sits as the final layer of Checkmarx SAST, and the same model is coming to other scan types, extending coverage across the full application development lifecycle so security doesn’t stop at detection. It is not the layer every team starts with. It is the layer teams reach for once standard scanner coverage is no longer enough, when getting a finding right matters as much as finding it fast. 

That need is only growing. New models keep arriving faster than security roadmaps can account for, and each one can change what attackers are able to find and exploit. Claude Mythos Preview’s hour-long path from patch to exploit showed what that looks like in practice: a working exploit within an hour of a patch being released.

A scanner built only to catch what it already knows will always be one step behind. Checkmarx Fusion exists to close that gap for teams that need deeper validation and greater confidence in what they are shipping.  

The apprentice’s mistake wasn’t casting the spell. It was assuming he could still control however many brooms showed up. Checkmarx Fusion is built for the version of that story where the brooms keep coming faster than anyone planned for, and someone still has to know which ones matter. 

Visit the Checkmarx Fusion landing page. Read more on the Checkmarx blog or in the documentation

Tags:

AI

AppSec

Article

Developer