Opinion

The AI Trust Report Card: 12 Months, 8 Studies, One Brutal Conclusion

Eight 2026 studies tell one story: ungoverned AI produces more code, more risk, and less value. Governance is the fix.

The AI Trust Report Card: 12 Months, 8 Studies, One Brutal Conclusion

Twelve months of data just landed in one place, and the conclusion is brutal. Across eight major studies published in 2026, the same pattern shows up from every angle: ungoverned AI produces more code, more risk, and less value. The people selling raw AI generation would rather you not read these numbers together. Here they are anyway.

What does the report card actually say?

  • 45% of AI-generated code contains OWASP-listed vulnerabilities, per Veracode.
  • 82% of organisations have shipped AI-written code that failed in production, per New Relic and Harness.
  • 88% have experienced a breach tied to an AI agent, per AvePoint.
  • 29% of developers trust AI output, down from 40% a year earlier, per Stack Overflow.
  • 180% more code written, but only 30% more shipped, per MIT.
  • 40% of AI spend delivers no measurable ROI, per Bain.
  • 88% of AI agent pilots never reach production, per Forrester and Anaconda.
  • 3% of organisations feel fully prepared to govern AI, per SAP and Oxford.

Read them as a set and the story isn't "AI is failing." It's that AI without a governing layer is failing. The technology works. The way most teams are deploying it doesn't.

Why is trust going down while capability goes up?

The Stack Overflow number is the one that should make you pause, because it runs against every marketing slide. Models got dramatically better in 2026, and developer trust still fell from 40% to 29%. The explanation is simple: developers aren't judging the model's best answer. They're judging its worst one. As models got more confident and more verbose, the failures got more plausible, and plausible failures are worse than obvious ones. Trust doesn't track capability. It tracks reliability, and reliability is exactly what raw generation doesn't guarantee.

The practical consequence is that teams are quietly re-adding the human review step AI was supposed to eliminate. Code review, security scanning, QA, they're all coming back, because nobody trusts the raw output. That's not a failure of AI. It's a recognition that generation and verification are different jobs, and AI only solved the first one.

The security numbers are the scariest

Forget the productivity charts for a second. Veracode found OWASP vulnerabilities in 45% of AI-generated code, and AvePoint found that 88% of organisations have had an AI agent breach. Those two numbers together mean the risk isn't theoretical and it isn't rare. It's the default. Code that's generated fast and shipped without a security review is how you get vulnerabilities in production, and agents that run with borrowed permissions are how you get breaches. The common thread is the same as everything else on the card: nobody put a governing layer between the model and the runtime.

Why is 40% of the spend producing nothing?

Bain's 40% no-ROI figure is the one finance teams actually notice, because it's the number that shows up in the budget. The reason is the same as the MIT finding: teams buy AI for its promise of velocity, then discover that generated output doesn't survive review, so the velocity evaporates into rework. You don't get the ROI from generating more. You get it from shipping more that holds up. And shipping more that holds up is a verification problem, not a generation problem.

What's the one pattern underneath all of it?

Ungoverned generation. Every one of those numbers traces back to the same root: teams are letting models produce output, then shipping it without a deterministic, auditable layer between the model and the runtime. More code, more surface area, less verification. That's the entire report card in one sentence.

The MIT number is the tell. 180% more code and only 30% more shipped means the model is generating a huge volume of stuff that mostly doesn't survive contact with production. It's not that the code is useless. It's that there's no gate between "generated" and "shipped," so most of it either breaks or gets thrown away. You can't out-generate a missing review step.

Three percent feel prepared, and they're right

The SAP and Oxford finding that only 3% of organisations feel fully prepared to govern AI is the most honest number on the card, because it's the one that predicts all the others. If almost nobody has the governance in place, then the vulnerabilities, the breaches, and the failed deployments aren't surprises. They're the predictable output of a capability that arrived faster than the controls around it. The 3% aren't being modest. They're describing reality.

A report card this bad usually triggers a retrenchment, and that's exactly what's happening in enterprise buying. Teams that spent 2025 adding AI everywhere are now asking which of it they can actually govern. The answer, increasingly, is the parts that run on a platform that governs by default.

Why does no-code flip this around?

Because structured no-code removes the exact thing that's going wrong. It eliminates the vulnerability surface by not letting you hand-write or hand-generate arbitrary code that runs wherever it likes. It gives visual verification, so a human can see what the app does before it ships. It delivers deterministic behavior, because the non-AI parts run through a defined runtime. And it bakes governance into the runtime, so permissions, audit trails, and controls aren't an afterthought. Those are precisely the four things the report card says are missing.

Concretely: when a no-code platform lets an AI generate a form or a workflow, the output lands inside a model where every field already has a permission and every change is already logged. The AI proposes. The platform governs. The human verifies. That pipeline is the difference between the 45% vulnerability rate and something a security team will actually sign off on.

So the "no-code is dead" crowd has it backwards?

Completely. The argument that AI makes no-code obsolete assumes the hard part of building software is producing code. It isn't, and 2026's data proves it. The hard part is shipping something safe, verified, and governed. AI makes producing code trivial, which makes the governance layer more valuable, not less. No-code platforms are, at their core, governance layers with a builder attached. AI hands them the exact problem they were built to solve.

What should you actually do with these numbers?

Stop measuring AI success by how much you generate. Start measuring by how much survives to production, how much is auditable, and how much you'd trust in front of a regulator. The 40% of AI spend with no ROI and the 88% of pilots that never ship are the same failure wearing two masks: generation without governance. Fix the governance and both numbers move.

Build with the governance layer first, whether you call it no-code or not. The thing that turns this report card around is a runtime that constrains what the AI can do, logs what it did, and lets a human verify before it ships. If your stack doesn't give you that, you're going to end up as one more data point in next year's report card.

The takeaway

Eight studies, one conclusion. Ungoverned AI produces more code, more risk, and less value. The fix isn't to stop using AI. It's to run it through a layer that verifies, audits, and constrains it, which is exactly what structured no-code is. AI doesn't kill no-code. It makes it the only sane place to build.

Want to read
more articles
like these?

Become a NoCode Member and get access to our community, discounts and - of course - our latest articles delivered straight to your inbox twice a month!

Join 10,000+ NoCoders already reading!