Jack Cable warns AI coding agents introduce bugs 40% of the time

AI Engineer////3 min read

The Shift to Autonomous Vuln Discovery

Frontier AI models are no longer just autocomplete assistants. They are morphing into autonomous agents capable of discovering and exploiting software flaws at a scale we have never seen. Jack Cable, co-founder and CEO of Corridor, calls this shift the "AI bugpocalypse." While developers adopt tools like Cursor and GitHub Copilot to ship code faster, they simultaneously hand attackers a highly scalable, automated pipeline to find zero-day vulnerabilities in the open-source foundations we all rely on.

The Reality of AI-Generated Bugs

This is not a theoretical threat. AI models write code that is notoriously buggy. Academic benchmarks like Backsbench show that even elite models introduce vulnerabilities 20% to 40% of the time. Because these models are trained on historical human code repositories, they naturally reproduce our worst habits. Worse, they struggle with contextual logic. While a model might avoid simple syntax errors, it often misses deep, domain-specific security rules like internal authorization structures. When developers merge this code with minimal review, they invite catastrophe into production environments.

Jack Cable warns AI coding agents introduce bugs 40% of the time
The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

Why We Must Abandon the Game of Whack-a-Mole

Defenders cannot patch their way out of this crisis. Pouring millions of dollars into finding and fixing individual, one-off bugs is a losing strategy. Instead, security teams must design software to be fundamentally resilient against entire vulnerability classes. This means leaning heavily into the "Secure by Design" philosophy.

If we look at common vulnerability tables, the same vintage issues crop up repeatedly. Buffer overflows, for instance, have plagued systems for thirty years. Yet, we have a concrete cure: memory-safe languages. Shifting codebases to languages like Rust or Go eliminates memory safety bugs entirely. Google proved this by migrating portions of Android to memory-safe languages, slashing the OS's memory safety bug share from 75% in 2019 to just 30% in 2022.

Guardrails and Policy for a Post-Bug Era

Security teams cannot simply ban AI tools. Engineering velocity is too critical to throttle. The answer lies in deploying automated guardrails that intercept vulnerabilities before they hit pull requests. Within the next year, AI will likely conduct the majority of code reviews, requiring robust validation engines to watch over the automated code generators.

On the policy front, restricting access to frontier models is a flawed approach. Because open-weight models catch up rapidly via distillation, adversaries will inevitably hold these capabilities. Policymakers must focus on supporting secure open-source development, funding systemic language rewrites, and maintaining competitive, domestic open-weight models to keep defenders armed with the best tools available.

Topic DensityMention share of the most discussed topics · 13 mentions across 13 distinct topics
Amazon
8%· companies
Android
8%· products
Anthropic
8%· companies
Backsbench
8%· products
Corridor
8%· companies
Other topics
62%
End of Article
Source video
Jack Cable warns AI coding agents introduce bugs 40% of the time

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor

Watch

AI Engineer // 19:44

We turn high signal in-person events for the top AI engineers, founders, leaders, and researchers in the world into the best free learning opportunities for millions around the world here on YouTube. Your subscribes, likes, comments, speaking, attendance, or sponsorships goes a long way toward making our biz model sustainable indefinitely. We strongly believe this industry deserves a better class of community and that we know how to do this well; we just need your support.

Who and what they mention most
Anthropic
26.9%21
Claude
21.8%17
OpenAI
19.2%15
Cursor
15.4%12
3 min read0%
3 min read