Artificial intelligence is dramatically accelerating the pace of software development, but it is also creating a new problem for enterprises: Organizations are producing code faster than security teams can realistically review, patch and defend, according to Moody’s Ratings.
The imbalance is widening the window of opportunity for cybercriminals while turning cybersecurity into a growing credit risk for companies, said Leroy Terrelonge, vice president of cyber credit risk at Moody’s, in an interview with The AI Innovator.
“We saw that cyberattacks and cyber incidents were having more of a credit impact on the issuers that we rate,” Terrelonge said. “If there’s an organization shut down, they’re no longer able to do their business as usual. They can have a financial impact, they can have a reputational impact. There can be regulations as a result. There can be lawsuits as a result.”
Moody’s evaluates whether cyber incidents can materially affect an issuer’s ability to meet its financial obligations, making cybersecurity an increasingly important factor in credit analysis.
Need more clues? Ask the Sherlock chatbot in the lower right corner to summarize this story, explain technical concepts or answer other questions.
Although cyber incidents have directly resulted in only about 30 Moody’s ratings actions to date, Terrelonge said most have occurred within the past few years, reflecting the growing financial consequences of cyberattacks as organizations become increasingly dependent on technology.
“We think it’s going to increase as the dependence on technology increases and as technology itself evolves,” he said.
New risks from AI-generated code
The concern extends beyond AI helping hackers launch attacks. AI is simultaneously helping developers discover vulnerabilities while also enabling organizations to generate vastly more code – often created by people with limited software or cybersecurity expertise.
That surge in software production could ultimately expand the number of vulnerabilities enterprises must defend.
“Just because you have access to an AI tool doesn’t mean that you understand good security practices,” Terrelonge said.

One common mistake involves developers embedding usernames, passwords or API keys directly into AI-generated code because it is the easiest approach.
“It’s a well-known security no-no to hard-code your security credentials inside of code,” he said. “But if you don’t work in security, you might not know that.”
AI-generated code can also reproduce insecure programming techniques that have existed for decades because the models are trained on imperfect human-written code. AI coding assistants may suggest coding patterns that contain known weaknesses or even hallucinate insecure implementations. Less experienced developers may accept the recommendations without recognizing the risks.
“We know that these AI tools hallucinate,” Terrelonge said. “Somebody who doesn’t know just by looking at the code what is more secure or what is less secure, they might just take what they’re given and use something that could expose them to more harm.”
The dangers of vibe coding
The concern is amplified by the rise of “vibe coding,” in which users describe applications in natural language while AI writes much of the software.
Rather than replacing professional developers, the technology is enabling employees across organizations to build internal tools and automate workflows without deep security expertise.
An employee, for example, might use AI to create a personal application that automatically logs into company systems or retrieves data every morning. Even if that software never becomes an official company product, insecure coding practices such as embedding credentials could create new attack paths if the employee’s device is compromised.

“It depends on what it’s being used for,” Terrelonge said. “It could be going into a product for the company,” where formal reviews typically occur. But employees also create software strictly for personal productivity, outside standard software development processes.
Meanwhile, security teams increasingly use AI-powered static code analysis to inspect software for vulnerable programming patterns before deployment. AI also is improving “fuzzing,” a longstanding technique that bombards software with unexpected inputs to expose hidden flaws.
Researchers are now building autonomous AI systems capable of scanning large code bases, identifying vulnerabilities and validating potential exploits with minimal human intervention.
“We’re getting very, very close” to AI systems that can perform an entire chain of vulnerability discovery automatically, Terrelonge said.
Security teams struggle to keep pace
Software bugs have become one of the leading ways cybercriminals gain access to corporate networks after several years during which social engineering and phishing dominated many attacks.
For a long time, hackers focused on tricking humans as people have historically been the weakest security link. “But now the tides have turned at least for a little bit,” Terrelonge said. “These more technical attacks relying on software vulnerabilities are becoming more feasible and more effective for these cyber criminals.”
As AI is finding bugs faster than many organizations can remediate them, attackers are weaponizing newly disclosed vulnerabilities increasingly quickly, leaving enterprises exposed for longer periods, according to Moody’s.

Moody’s noted that nearly 48,000 new bugs were found in 2025 alone. Its analysis also found that about 60% of the nearly 9,500 organizations it rates had at least one known bug that was exploited by hackers on their networks last year, and nearly 40% had one that remained unpatched for at least 45 days – the time it takes attackers to exploit them. More than a quarter had at least one known bug for over a year.
Globally, Moody’s finds that Japanese and Korean companies are more likely to have unpatched known bugs in their networks compared to North American and Western European companies. As for sectors, education, telecom and technology have more known bugs than banks and utilities.
Large enterprises generally maintain structured review processes before code reaches production, including testing and peer review, according to Terrelonge. But smaller organizations and startups often lack comparable resources, increasing the risk that insecure code reaches production under pressure to ship products quickly.
Vendors are a common target
Third-party software suppliers present another growing concern.
“We see in general that third-party vendors are one of the most common ways that issuers – the entities that we rate at Moody’s – are being attacked,” Terrelonge said.
Large enterprises have strengthened their own cyber defenses, making suppliers with weaker security controls increasingly attractive targets. Those vendors frequently maintain trusted connections into customer networks, allowing attackers to move into larger organizations after compromising smaller partners.
Could AI-generated applications at vendors become another source of supply-chain risk? “I think it’s certainly possible,” Terrelonge said.
For enterprise leaders, the message is not to avoid AI coding assistants but to treat them as productivity tools rather than security experts.
AI can dramatically accelerate software development and discovery of enterprise vulnerabilities. But without secure development practices, it can also increase the amount of insecure software in business systems – changing what’s an IT challenge into a growing business and credit risk.








Meanwhile, Microsoft continues to push forward with its cloud computing services, adding new tools for businesses looking to streamline their operations. These developments signal a continued focus on innovation and user experience across the tech industry. As these companies grow, their decisions will undoubtedly shape the future of technology.