AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to register
15automated residualNeeds reviewAbove working threshold (12)

AI-authored software vulnerabilities

Owner · Tool vendors, OSS maintainers, CISOs

CapabilityDomain knowledgeAffordanceCap-adjacent

Statement (NASA form)

Given that AI coding tools are already in the provenance of public CVEs, and they are being adopted as the default author of new code, there is a possibility of a correlated class of bugs shipping across many products at once resulting in a software ecosystem whose defects an attacker can study once and exploit many times.

Condition
AI coding tools are already in the provenance of public CVEs, and they are being adopted as the default author of new code
Departure
a correlated class of bugs shipping across many products at once
Impact
a software ecosystem whose defects an attacker can study once and exploit many times

VC + institute corroboration

Experimental share of compiled public capital that names this risk. Not a certified residual.

$47Mexperimental share · $23M private / $25M institute · strong corroboration
  • Gray Swan · $40M Series A + ~$10M prior
  • HiddenLayer · ~$50M reported
  • UK AISI · ~$20M of published budget mapped here
  • CAISI · ~$4.5M of published budget mapped here

2 public sources · OECD AIM · OWASP LLM Top 10 2026

Worst scenario
3×4
Probable × Critical
Urgency
3
Priority · This quarter
Inherent composite
15
Worst 12 + urgency
Residual composite
15
Need ≤ 12

Human bugs are idiosyncratic. Model bugs rhyme. If the same assistant writes the auth middleware for a thousand startups, a single misunderstanding becomes a thousand CVEs with the same shape.

Pathway fragment

Simple upstream → via → downstream notes. Not a causal graph. Experimental.

Upstream
  • Model-authored code at volume
  • Reviewers stamping plausible patches
Via
  • Rhyming bug or quiet backdoor
  • Shipped library
Downstream
  • Class of systems with the same hole
  • Supply-chain incident

Assumptions · Origin-marking in IDEs is not treated as in place for most teams.

Human calibration

Override is stored on this desk only. It does not make the score official.

Failure scenarios

Each scenario has its own likelihood and consequence. The risk takes the most severe cell. Residual applies implemented mitigations to every scenario, then re-ranks.

A single product ships a model-authored RCE

5Extremely likely2Minor10

Ordinary, already happening. Consequence is local until it is not.

A rhyming auth bug across a generation of apps

3Probable4Critical12

One exploit pattern opens hundreds of products that never shared a codebase.

A generated patch poisons a widely used library

2Remote5Catastrophic10

A helpful model lands a plausible fix that introduces a backdoor-shaped mistake.

Examples

Georgia Tech CVE tracking

Public tracking has confirmed AI coding tools in the provenance of disclosed vulnerabilities.

Default author

In many teams the model now writes the first draft of every function. Reviewers approve the shape, not the invariant.

Dependency rhyming

Generated code prefers the same libraries and the same wrong defaults. The attack surface is a chorus.

Contributing signals

X posts on the desk that evidence this risk. A signal can contribute to more than one risk.

AI coding tools confirmed in public CVE provenance.

Mitigations

Residual assumes only items marked in place. Highlighted rows are the remaining work needed to reach a composite of 12.

In progressIDE and VCS vendors

Provenance tags on generated code in the review UI

Reviewers must know which lines a model wrote. Blind approval is the current default.

IDE and VCS vendors · expedited 3 weeks · normal 3 months · −0 L · −0 C · −1 U

ProposedCISOs

Diversity requirements on critical paths

Auth, crypto, and payments are not written by a single model family without a second implementation.

CISOs · expedited 4 weeks · normal 4 months · −1 L · −1 C · −0 U