A single product ships a model-authored RCE
Ordinary, already happening. Consequence is local until it is not.
AI Risk Atlas Prototype/Demo — Unofficial independent experiment. Not an official xAI product. Scores can be wrong.
Owner · Tool vendors, OSS maintainers, CISOs
Statement (NASA form)
Given that AI coding tools are already in the provenance of public CVEs, and they are being adopted as the default author of new code, there is a possibility of a correlated class of bugs shipping across many products at once resulting in a software ecosystem whose defects an attacker can study once and exploit many times.
- Condition
- AI coding tools are already in the provenance of public CVEs, and they are being adopted as the default author of new code
- Departure
- a correlated class of bugs shipping across many products at once
- Impact
- a software ecosystem whose defects an attacker can study once and exploit many times
Experimental share of compiled public capital that names this risk. Not a certified residual.
2 public sources · OECD AIM · OWASP LLM Top 10 2026
Human bugs are idiosyncratic. Model bugs rhyme. If the same assistant writes the auth middleware for a thousand startups, a single misunderstanding becomes a thousand CVEs with the same shape.
Simple upstream → via → downstream notes. Not a causal graph. Experimental.
Assumptions · Origin-marking in IDEs is not treated as in place for most teams.
Override is stored on this desk only. It does not make the score official.
Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.
Ordinary, already happening. Consequence is local until it is not.
One exploit pattern opens hundreds of products that never shared a codebase.
A helpful model lands a plausible fix that introduces a backdoor-shaped mistake.
Public tracking has confirmed AI coding tools in the provenance of disclosed vulnerabilities.
In many teams the model now writes the first draft of every function. Reviewers approve the shape, not the invariant.
Generated code prefers the same libraries and the same wrong defaults. The attack surface is a chorus.
X posts on the desk that evidence this risk. A signal can contribute to more than one risk.
AI coding tools confirmed in public CVE provenance.
Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.
Reviewers must know which lines a model wrote. Blind approval is the current default.
IDE and VCS vendors · expedited 3 weeks · normal 3 months · −0 L · −0 C · −1 U
If a model wrote it, a machine must also try to break it before a human stamps it.
Engineering orgs · expedited 2 weeks · normal 2 months · −1 L · −1 C · −0 U
Auth, crypto, and payments are not written by a single model family without a second implementation.
CISOs · expedited 4 weeks · normal 4 months · −1 L · −1 C · −0 U