AI Security Gap: Why Governance and Developer Support Must Catch Up
New insights reveal how AI-driven development is outpacing security - and what organizations must do to adapt.
PITTSBURGH, Pa., July 16, 2025 /PRNewswire/ -- Security Journey, a leading provider of application security education, has released a new report outlining the security challenges posed by AI adoption in software development, and the steps organizations must take to close the growing gap between how software is built and how it is secured.
The report, Closing the Security Gap in AI, captures insights from a roundtable held in June 2025, featuring leading voices in application security, development, and AI. The panel explored how AI tools, particularly large language models and code generation assistants, are transforming software workflows, often at the expense of security. Developers are releasing code faster, but often without fully understanding the implications of using AI in the development lifecycle.
Security Journey's roundtable participants - including security leaders, engineers, and educators from across the industry - discussed the real-world consequences of AI-generated vulnerabilities, the risks of over-relying on automation, and the cultural and structural changes required to support secure AI adoption.
The report pinpoints where organizations must adapt to secure their use of AI, including:
- Governance must reflect reality: AI policies are often developed without a clear understanding of how teams truly engage with the technology. When governance is overly rigid or reactive, it drives employees toward shadow AI - exacerbating risk rather than mitigating it.
- Developers need greater support and accountability: AI is shifting more decision-making onto developers, many of whom lack the security knowledge to assess risks. Organizations must provide proactive education and just-in-time support.
- Security culture needs to evolve with the tech: Teams will only prioritize security if it is integrated into their daily routines and reinforced by peers. Positive reinforcement, clear defaults, and internal champions can help normalize secure behavior.
- AI is accelerating talent gaps: Overreliance on AI tools is preventing junior developers from building foundational experience. Organizations risk losing long-term expertise unless they invest in both human and technical development.
- Security May Get Worse Before It Gets Better: Threat actors are already taking advantage of vulnerabilities in AI-generated code. As organizations struggle to keep pace, the frequency of incidents may continue to rise. The path forward demands education, rigorous testing, and a shift in security culture
"This isn't a tooling problem - it's a people problem," said Dustin Lehr, AppSec Advocate at Security Journey. "From boardrooms to codebases, the pressure to adopt AI is accelerating. It's transforming how software is created, but developers remain accountable for securing it. If we don't match the speed of AI adoption with equally aggressive education and governance, we risk exposing organizations to systemic vulnerabilities. Developers need more than policies - they need training, support, and a culture that empowers secure choices. This report doesn't just highlight the challenges - it offers a roadmap to close the gap."
To read the full insights and recommendations, download the complete report: Closing the Security Gap in AI.
About Security Journey
Security Journey empowers organizations to reduce vulnerabilities by teaching developers and everyone in the software development lifecycle (SDLC) how to build secure applications. With a programmatic approach to secure coding education, Security Journey offers an extensive library of video-based lessons, and hands-on coding exercises in sandbox environments. By strengthening foundational knowledge and fostering a security-first mindset, Security Journey helps teams address vulnerabilities at the source, bridging the gap between security and development to create a culture of secure software development. Learn more and start building security into your code at www.securityjourney.com.
View original content:https://www.prnewswire.com/news-releases/ai-security-gap-why-governance-and-developer-support-must-catch-up-302506745.html
SOURCE Security Journey