Survey Surfaces Raft of AI Coding Issues Involving Embedded Systems
A recent survey of 785 development and security professionals involved with embedded systems reveals that 89% of organizations are currently utilizing artificial intelligence (AI) coding assistants. However, 39% of respondents indicated that only select…
A recent survey of 785 development and security professionals involved with embedded systems reveals that 89% of organizations are currently utilizing artificial intelligence (AI) coding assistants. However, 39% of respondents indicated that only select developers are permitted to use these tools.
The survey, conducted by Censuswide for Black Duck Software, highlights that 96% of participants are incorporating open source AI models into their products. Despite this widespread adoption, there are concerns regarding governance and security measures. Notably, 21% of respondents lack confidence in their ability to prevent AI-related security vulnerabilities, and 18% express uncertainty in managing open source license risks associated with AI-generated code.
The survey indicates that Python is the most frequently used programming language for embedded systems (27%), followed by C++ (26%), Java (22%), and JavaScript (21%). The use of software composition analysis (SCA) tools is becoming more prevalent, with 39% of respondents conducting scans on every build and pull request, and 35% conducting scans within the integrated development environment.
However, 39% of respondents indicated that only select developers are permitted to use these tools.
A significant 71% of organizations are now able to produce software bills of materials (SBOMs), motivated largely by customer and partner requirements (40%). Despite challenges in creating accurate SBOMs, 80% of respondents are confident in their organization's ability to produce a complete and accurate SBOM when needed.
Risk Management and Security Challenges
The survey also points to a gap between management and engineers regarding project success. While 86% of Chief Technology Officers (CTOs) and directors consider their projects successful, only 56% of developers share this view. Historically, embedded systems have been attractive targets for cybercriminals, particularly because legacy platforms often lacked updates to enhance cybersecurity resilience.
As the deployment of embedded systems expands, the attack surface requiring defense continues to grow. This expansion may challenge cybersecurity teams, who could become overwhelmed by the volume of vulnerabilities in embedded systems, which could have been mitigated with proper measures.
Based on reporting by devops.com.
