BSIMM16: navigating software security amidst AI, regulation, and supply chain challenges

Exploring BSIMM16's insights on AI-driven security challenges, regulatory pressures, and evolving software practices across industries.

  • Monday, 16th February 2026 Posted 4 months ago in by Sophie Milburn

Black Duck, an AI-powered application security solutions provider, recently unveiled the 16th edition of the Building Security In Maturity Model (BSIMM16). This study aims to shed light on the evolving landscape of software security, particularly in the face of emerging AI, regulatory demands, and agile security training approaches.

AI has emerged as the leading force reshaping application security priorities, marking an important moment in BSIMM's history.

The study, encompassing assessments from 111 organisations within various sectors such as financial services, healthcare, technology, and independent software vendors (ISVs), provides insights. These organisations represent over 223,700 developers working on safeguarding about 91,200 applications.

Key Trends in Application Security:

  • AI as a Defining Challenge: The report reveals an increase in teams using attack intelligence and risk-ranking to ensure AI-generated code safety.
  • Regulatory Influence: Increased by global mandates, there is a heightened focus on software supply chain transparency with increased production of Software Bill of Materials (SBOMs) and automated infrastructure verification.
  • Software Supply Chain Emphasis: Organisations are now prioritising ecosystem-wide security. There's a rise in adopting standardised technology stacks and deploying SBOMs as core essentials.
  • Transformation in Security Training: Traditional courses are transitioning to bite-sized learning models, facilitating instant access to security expertise via collaborative channels.

Jason Schmitt, CEO of Black Duck, commented on the evolving landscape, highlighting how AI-generated code may mislead developers with an "illusion of correctness." Adopting SBOMs can help provide transparency by clearly identifying the components within software.

With impending regulatory expansions, such as the EU Cyber Resilience Act, SBOMs are evolving from compliance tools into important infrastructure managing the risks associated with AI-driven software development.

An examination of how Atlassian’s Rovo and Teamwork Graph introduce AI-driven automation into...
The 2026 ExtraHop Global Threat Landscape Report uncovers AI's dual role as both a defender and...
Zero Networks' latest report reveals security risks within enterprise environments, emphasising the...
e2e-assure launches Cumulo, a sovereign AI-driven SOC platform, developing cyber defence...
Unlimitail partners with Snowflake to launch Global Retail Media Data Hub, enhancing retail media...
SentinelOne’s new AI-driven automated investigations aim to enhance security operations by...
CrowdStrike expands Project QuiltWorks to include AWS, with capabilities designed to address AI...
Explore the widening gap between AI advancement and data sovereignty across EMEA, highlighting...