AI-generated dependencies can outpace security remediation

AI coding is increasing open-source remediation workloads
ActiveState has published findings from a survey of 300 enterprise security and engineering leaders examining how AI coding affects open-source risk. The research, presented in its AI Coding and Open Source Risk webinar, focuses on a growing operational challenge: generated code can introduce dependencies faster than security teams can assess and remediate them.
AI-assisted development can speed routine work and increase the volume of code produced. But the security work associated with that code does not disappear. When a developer adds an open-source package, teams may need to review vulnerabilities, licensing, maintenance status, ownership and whether the dependency belongs in the environment at all.
Dependency growth creates remediation debt
ActiveState describes the accumulating backlog as remediation debt: unresolved security work that grows when new dependencies and findings arrive more quickly than a team can close them. The concern is not AI coding in isolation, but the speed at which it can expand an organisation's software supply chain.
A dependency may be introduced in minutes, while the work of validating and governing it takes longer. This imbalance can leave vulnerability reviews, licensing checks and maintenance decisions waiting downstream. As AI tools become more autonomous, ActiveState says the gap between generated code and the capacity to govern its components could widen significantly.
Benchmarking controls against enterprise peers
The survey spans leaders in technology, financial services, healthcare, manufacturing and government. It examines how organisations handle AI-driven open-source risk, where remediation programmes struggle, and how accumulated debt relates to audit failures, breach frequency and lost productivity.
The webinar is presented by ActiveState's Rebecca Banks and Moris Chen. It addresses changes in remediation workloads, comparisons with 300 enterprise peers, the point at which debt affects security and business outcomes, and governance models that organisations are using today.
What security and engineering leaders should examine
The findings frame AI adoption as a governance and capacity question as much as a development-speed question. More generated code can mean a larger inventory of third-party components, each requiring a defined review and remediation path.
For businesses, the practical implication is to compare the rate at which AI-enabled development adds open-source dependencies with the capacity to review, assign, maintain and remediate them, so unresolved work is identified before it becomes a persistent backlog.

