[ MSP.DD ] For investors and founders · Updated
How risky is AI-generated code in an acquisition target?
Short answer
Riskier than most buyers assume. In Veracode's 2025 tests, AI models introduced security flaws in 45% of coding tasks, and Software Improvement Group reports roughly twice as many security-risk violations in AI-generated code. The risk isn't AI code as such. It's AI code that shipped without review or tests.
Why it matters
Many startups now write a large share of their code with AI tools. If that code wasn't reviewed, the buyer inherits vulnerabilities and maintenance cost that never show up in a demo.
How to check
- 01Measure how much recent work carries AI-tool markers in the commit history, knowing this undercounts.
- 02Check whether AI-written changes went through code review and automated tests.
- 03Run dependency and secret scans on the full history, not only the latest version.
- 04Sample AI-marked changes in security-sensitive code: authentication, payments, data access.
- 05Ask for the team's written policy on AI coding tools.
Red flags
- Large AI-written changes merged without review.
- No tests around authentication or payment code.
- Keys or secrets committed anywhere in the history.
Good signs
- AI-written changes are reviewed like any other code.
- Security scanning runs in the build pipeline.
- A written policy on which AI tools may be used, and where.
The numbers
- Veracode tested more than 100 language models on 80 curated coding tasks and found they introduced security flaws in 45% of them. [1]
- In the same tests, Java had the highest failure rate, above 70%. Python, C# and JavaScript fell between 38% and 45%. [1]
- Software Improvement Group cites experiments in which AI-generated code produced roughly twice as many security-risk violations as comparable human-written projects. [2]