AI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh Salhotra @OWASPGLOBAL
AI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh Salhotra  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
The potential benefits are substantial as organizations increasingly adopt AI-driven code-generation tools to enhance productivity and streamline development workflows. Code generation offers transformative advantages, from accelerating development cycles to minimizing manual errors.

However, this technological advancement introduces a range of risks that, if not adequately understood and managed, could pose significant challenges. Key risks include security vulnerabilities, code quality issues, potential copyright infringement, data breaches, and the possibility of reverse engineering models. Additional concerns involve bias introduction, poisoning attacks, inefficient code generation, hallucinated dependencies, and an over-reliance on AI tools, potentially leading to increased technical debt over time. A comprehensive understanding and effective mitigation of these risks are essential to fully realizing the potential of code generation technologies.

A robust risk mitigation strategy is critical. Organizations must prioritize comprehensive code reviews, continuous monitoring of tools, and the implementation of rigorous testing frameworks. Establishing clear guidelines, adopting stringent security measures, and managing controlled rollouts are vital to minimizing vulnerabilities. Additionally, safeguards around data management, intellectual property protection, and sustainable code practices will ensure code generation tools’ long-term efficacy and security.

This talk will detail these risks, offering actionable insights and strategies for leveraging AI-driven code generation while mitigating associated risks. This will allow organizations to harness this technology’s full potential safely and effectively.

-

Managed by the OWASP® Foundation
owasp.org
AI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh SalhotraThe OWASP Events Committee Presents Vienna 26Keynote: Thriving in the Age of AI - Aanchal GuptaHidden Chains: Revealing High-Impact Bugs from Bounty submissions - Vinay & MuraliOWASP Global Board of Directors Meeting - February 2025Under the Radar: How we found 0-days in the Build Pipeline of OSS Packages - François Proulx202009 September 2020 Global Board MeetingThe SCA Balancing ActHow Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent BouchardThe Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin LehrLeaking Secrets in the Age of AI: How AI Adoption is Creating New Attack VectorsBuilding Security Into Developer Velocity: How We Made Entra Identity Compliance Invisible track 1
OWASP Foundation |

AI Code Generation - Benefits, Risks and Mitigation Controls - Aruneesh Salhotra

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER