# AI Is Building Your Attack Surface. Are You Testing It?

DevFeed: [AI Is Building Your Attack Surface. Are You Testing It?](<https://devfeed.tech/articles/ai-is-building-your-attack-surface-are-you-testing-it-7806.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ai-is-building-your-attack-surface-are-you-testing-it/>)

Author: Manoj Nair

Published: 2026-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [code security](<https://devfeed.tech/topics/code-security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [Back end](<https://devfeed.tech/topics/backend.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code](<https://devfeed.tech/tags/code.md>), [code-generation](<https://devfeed.tech/tags/code-generation.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [coding](<https://devfeed.tech/tags/coding.md>), [executive](<https://devfeed.tech/tags/executive.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [testing](<https://devfeed.tech/tags/testing.md>)

## AI overview

AI-generated code is accelerating development while introducing serious security risks: 62% of LLM-generated backend code evaluated by BaxBench was broken or insecure, and about half of the code that worked remained exploitable. The article argues that static analysis is necessary but insufficient, and that runtime testing is needed to assess real exploitability. It also highlights AI agents as an expanding attack surface because they increasingly call privileged and undocumented APIs.

## Source excerpt

Speed has outpaced validation. With 62% of LLM-generated code testing as insecure and AI agents using undocumented APIs, legacy tools fall short. Learn how Snyk's AI-powered dynamic testing secures your expanding attack surface.