To fight AI malware enterprises need Zero Trust for code
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Software security was built around human development.
People wrote, reviewed and deployed code. Now machines are taking over.
In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their AI model, Claude.
The same capabilities that make developers more productive are changing the economics of cyberattacks.
While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.
Most enterprise software security workflows assume there is time for review. Code is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.
That model breaks down when software moves from prompt to execution in minutes.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
AI-generated code can become a script, dependency, automation job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands.
Human reviewers are no longer in the loop.
Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.
While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.
Human attackers are not disappearing. But more of the attack chain is becoming machine-executed.


