A new study finds that while frontier AI coding models are hallucinating less than they did a year ago, they still preserve a significant amount of avoidable software risk when left ungrounded. Sonatype’s research shows that connecting these models to real-time software intelligence dramatically improves remediation quality and reduces critical and high-severity vulnerability exposure by 60–70%. The takeaway is clear: safer AI-assisted development will depend not just on better models, but on grounding them in accurate, current dependency and vulnerability data.
Segment Resources:
2026 State of the Software Supply Chain report: https://www.sonatype.com/state-of-the-software-supply-chain/introduction
This segment is sponsored by Sonatype. Read the study: https://securityweekly.com/sonatypersac
Read the interview summary from SC Media here: Sonatype’s Brian Fox on coding agents getting more cautious, but not safer
- 0:00 - – RSAC 2026 Intro & Sonatype Overview
- 0:35 - – What Sonatype Does (Maven, Nexus & Open Source Ecosystem)
- 02:16 - – What is Software Intelligence for AI Coding?
- 02:30 - – How AI Coding Tools Lack Real-Time Security Context
- 04:09 - – Feeding AI Agents Real Vulnerability & Dependency Data
- 05:04 - – The Risk of AI Choosing Deprecated or Vulnerable Code
- 05:16 - – AI Hallucinations vs Security Accuracy Explained
- 06:41 - – Why AI Became More “Cautious” (But Less Effective)
- 07:35 - – Hidden Risk: False Confidence in AI Security Reviews
- 08:40 - – Improving AI Accuracy with Grounded Data (MCP)
- 10:28 - – Using MCP Servers for AI Coding Intelligence
- 11:06 - – AI + Human Collaboration in Secure Development
- 11:44 - – The Future of Developers: AI as an Abstraction Layer
- 12:43 - – Natural Language as the New Programming Interface
- 13:45 - – Can AI Be Trusted in Secure Environments?
- 14:31 - – Why AI Must Follow Traditional Security Best Practices
Brian Fox is CTO and co-founder of Sonatype, with more than 20 years of experience spanning software development, open source, and cybersecurity. A founder of Maven Central and former chair of the Apache Maven project, he also serves in leadership and advisory roles with OpenSSF, FINOS, Singapore’s CTREX Panel, and the Apache Software Foundation.