2 Sources
[1]
Copilots and low-code apps are creating a new 'vast attack surface' - 4 ways to fix that
A typical enterprise has 80,000 apps built outside of the traditional development lifecycle, and 62% have vulnerabilities, a new study finds. It doesn't have to be this way. Today's average large enterprise is likely to have nearly 80,000 apps built out of copilots and low-code platforms. This is
[2]
Why copilots and low-code apps portend a security nightmare
A typical enterprise has 80,000 apps built outside of the traditional development lifecycle, and 62% have vulnerabilities, a new study finds. Here's how to fix this. Today's average large enterprise is likely to have nearly 80,000 apps built out of copilots and low-code platforms. This is posing a
Share
Copy Link
AI copilots and low-code applications are revolutionizing software development, but they also introduce new security risks. This article explores the potential vulnerabilities and suggests ways to mitigate them.

The software development landscape is undergoing a significant transformation with the advent of AI copilots and low-code applications. These technologies are democratizing coding, allowing non-developers to create applications and experienced developers to work more efficiently. However, this revolution comes with its own set of security challenges that organizations need to address
1
.As more individuals gain the ability to create applications, the potential attack surface for cybercriminals expands dramatically. This proliferation of amateur-developed software introduces vulnerabilities that may go unnoticed by inexperienced creators. The situation is further complicated by the fact that AI copilots, while helpful, can sometimes generate insecure code snippets that developers might implement without proper scrutiny
2
.AI copilots, despite their benefits, can inadvertently introduce security flaws into applications. These tools may suggest code that contains vulnerabilities or outdated practices, which could be exploited by malicious actors. Moreover, developers might over-rely on these AI assistants, potentially leading to a decrease in code quality and security awareness
1
.Low-code platforms, while enabling rapid application development, often abstract away important security considerations. This abstraction can lead to applications with weak security postures, especially when created by users without a strong background in cybersecurity. Additionally, the ease of creating and deploying applications may result in a proliferation of shadow IT, making it difficult for organizations to maintain oversight and security standards
2
.Related Stories
To address these security challenges, experts recommend several strategies:
1
.As these new technologies gain traction, traditional development teams will need to adapt their roles. They may shift towards becoming guardians of code quality and security, reviewing and refining the output of AI copilots and low-code platforms. This evolution will require a blend of technical expertise and mentorship skills to guide less experienced creators towards secure development practices
2
.Summarized by
Navi
10 Jun 2026•Technology

09 May 2026•Technology

31 Mar 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
