Skip to content
Reality Graph

Data

AI Code Statistics 2026

Last updated: 2026-07-023 min read

The numbers behind AI coding, consolidated and sourced: 84% of developers use AI tools, 96% distrust the code and 48% consistently verify it; review time per PR is up 91%, two-week churn is drifting from ~3.1% toward 5.7%, and ~45% of AI-generated samples fail security tests. Every figure below carries its source and year. A living reference, updated as the research moves.

moduleclassclassfnfnfnfncheckout.py:118
Contents

Adoption and the verification gap

The gap between 96% distrust and 48% verification is the sector's defining number; every figure carries its source and year.
FigureEvidence base
Developers using AI tools (up 14 pts from 2023)84%Stack Overflow survey · 2025Independent surveyEditorial classification · 2026-07
Developers who distrust AI-generated code96%Sonar, State of Code · 2026Vendor studyEditorial classification · 2026-07
Developers who consistently verify AI code48%Sonar, State of Code · 2026Vendor studyEditorial classification · 2026-07
Find AI code harder to review than a colleague's38%Sonar, State of Code · 2026Vendor studyEditorial classification · 2026-07
The gap between 96% distrust and 48% verification is the sector's defining number; every figure carries its source and year.

The gap between 96% and 48% is the sector’s defining number, unpacked in the verification gap.

The review bottleneck

Percentages, not universal wait-times: the direction - more volume, slower review - is consistent across sources.
FigureEvidence base
More merged PRs in high-AI teams+98%Faros AI telemetry · 2026Vendor telemetryEditorial classification · 2026-07
Review time per PR, same teams+91%Faros AI telemetry · 2026Vendor telemetryEditorial classification · 2026-07
Median time a PR spends in review+441%DORA-cycle telemetry · 2025Vendor-adjacent telemetryEditorial classification · 2026-07
Larger pull requests+51%DORA-cycle telemetry · 2025Vendor-adjacent telemetryEditorial classification · 2026-07
Experienced devs slower with early-2025 AI (while feeling faster)−19%METR randomized trial · 2025Academic RCTEditorial classification · 2026-07
Percentages, not universal wait-times: the direction - more volume, slower review - is consistent across sources.

The mechanics are in the review bottleneck; the METR result is the standing caution that perceived and real productivity diverge.

Code quality and churn

Vendor-adjacent GitClear signals, read as directional; churn is priced against the pre-AI baseline.
FigureEvidence base
Two-week churn trend as AI assistance grew~3.1% → 5.7%GitClear, 211M lines · 2025Vendor-adjacent analysisEditorial classification · 2026-07
Rise in duplicated code blocks~8xGitClear, 211M lines · 2025Vendor-adjacent analysisEditorial classification · 2026-07
Share of moved/refactored codedecliningGitClear, 211M lines · 2025Vendor-adjacent analysisEditorial classification · 2026-07
Vendor-adjacent GitClear signals, read as directional; churn is priced against the pre-AI baseline.

What the churn numbers do and do not say is in AI code churn, and their euro translation in the cost calculation.

Security

The load-bearing finding is that security stayed flat across model generations while functionality rose.
FigureEvidence base
AI-generated samples that fail security tests~45%Veracode · 2025Vendor studyEditorial classification · 2026-07
Relevant samples failing to prevent XSS (CWE-80)86%Veracode · 2025Vendor studyEditorial classification · 2026-07
Failure rate: Java / C# / JavaScript / Python72% / 45% / 43% / 38%Veracode · 2025Vendor studyEditorial classification · 2026-07
Security across model generations (functionality rose)flatVeracode · 2025Vendor studyEditorial classification · 2026-07
The load-bearing finding is that security stayed flat across model generations while functionality rose.

The classes and defenses are in security vulnerabilities in AI code.

Supply chain and secrets

Academic hallucination rates beside vendor secrets telemetry - the evidence base is marked per row.
FigureEvidence base
LLM-recommended packages that do not exist19.7%USENIX Security (Spracklen et al.) · 2025Academic studyEditorial classification · 2026-07
Unique hallucinated package names observed205,000+USENIX Security (Spracklen et al.) · 2025Academic studyEditorial classification · 2026-07
Hallucinated names repeating in all 10 reruns43%USENIX Security (Spracklen et al.) · 2025Academic studyEditorial classification · 2026-07
New hardcoded secrets on public GitHub in 202528.65MGitGuardian · 2026Vendor studyEditorial classification · 2026-07
Rise in AI-service secret leaks year over year+81%GitGuardian · 2026Vendor studyEditorial classification · 2026-07
Secret-leak rate of AI-assisted vs human commits~2xGitGuardian · 2026Vendor studyEditorial classification · 2026-07
Academic hallucination rates beside vendor secrets telemetry - the evidence base is marked per row.

These feed slopsquatting and what AI tools actually read.

What these numbers do not say

Three honest caveats. There is no robust industry figure for “what percentage of code is AI-generated” - the definitions and telemetry differ too much, so this page avoids that headline. Several key sources are vendor or vendor-adjacent (Sonar, Faros, GitClear, Veracode, GitGuardian). They are the best public data and carry an interest, so treat them as directional and prefer figures corroborated across independent signals - which most of the above are. And percentages describe direction and magnitude, not a universal multiplier: your codebase’s numbers come from measuring it, via the four metrics, not from ours.

Where Reality Graph fits

Reality Graph cites these numbers; it does not generate its own. There are deliberately no Reality Graph statistics on this page. The product is in private beta, and inventing product-performance figures would violate the same claim-safety rule the rest of the site follows. What Reality Graph does is let a team produce its own version of these numbers, from its own runs, via the evidence reports and metrics - measured, not borrowed.

This reference gives you

  • Every key AI-code figure with its source and year
  • Themed tables built for one-value citation
  • The independent-vs-vendor split, stated per source
  • A living page updated as the research moves

It does not give you

  • A robust 'X% of code is AI-generated' number - none exists
  • Any Reality Graph performance statistics
  • A universal multiplier for your codebase - measure it
  • Certainty from single vendor studies - direction over gospel
A cited reference, not a scoreboard: the numbers are the industry's, and none of them are Reality Graph's own.

FAQ

How much code is AI-generated, and how many developers use AI tools?
As of the 2025 Stack Overflow survey, 84% of developers use AI tools - up 14 points from 2023. A single reliable figure for the share of code that is AI-generated does not exist across the industry (definitions and telemetry differ), which is why this page reports adoption and effect rather than a headline 'X% of code' number that no source robustly supports.
How long do AI pull requests wait, and how much has review slowed?
Faros AI telemetry across thousands of teams reports review time per PR up 91% in high-AI-adoption teams, while merged PR volume rose about 98%. And DORA-cycle telemetry put the median time a PR spends in review up 441% as AI volume grew (2025). There is no universal wait-time in hours; the percentages describe the direction and magnitude, which are consistent across sources.
What is the single most-cited AI code statistic?
Sonar's 2026 finding that 96% of developers distrust AI-generated code while only 48% consistently verify it - the 'verification gap'. It is widely cited because it captures the whole problem in two numbers: the awareness is nearly universal, the diligence is not, and the difference is behavioral rather than technical.
Are these statistics from independent research or vendors?
Both, and this page marks which. Independent or academic: the METR randomized trial, the USENIX Security 2025 slopsquatting study. Vendor or vendor-adjacent (reliable but with an interest): Sonar, Faros AI, GitClear, Veracode, GitGuardian. We treat vendor figures as directional evidence, note them as such, and prefer numbers corroborated across independent signals.
How current are these numbers?
This is a living reference: it consolidates the sourced figures used across the site and is updated when new research lands or a number ages, with the visible date bumped. Each figure carries its own year in the tables, so you can see at a glance whether a statistic is from 2025 or 2026 rather than trusting a single 'last updated' stamp.
Can I cite these figures?
Yes - cite the underlying source named in each row and its year, not this page. The tables are organized to make that easy: value, precise description, source and year in every row. Where a figure is a range or a trend, cite it as one; the biggest error in AI-code statistics is quoting a spread as a point.

Keep reading

Sources

Want to see what your last agent run would have looked like?

Request access