Federal Analysis
DoD Addresses AI-Generated Code Risks
March 25, 2026
AI-generated code has become a significant component of defense software supply chains, with estimates indicating that between 20% and 30% of some code repositories are AI-derived. This integration introduces complex challenges for procurement, security, and oversight within the U.S. Department of Defense (DoD) and allied defense ministries. Procurement professionals must prioritize implementing robust verification processes, security-focused code reviews, and dynamic monitoring to mitigate vulnerabilities associated with AI-driven software development.
- Why this matters: The prevalence of AI-generated code in defense systems necessitates updated procurement requirements emphasizing software assurance and cybersecurity.
- Defense contractors and suppliers should prepare to demonstrate enhanced code verification and security practices to meet evolving DoD standards.
- Organizations involved in defense software development may find increased demand for tools and services that support AI code auditing, vulnerability detection, and continuous monitoring.
- Procurement teams should consider incorporating AI risk management criteria into contract solicitations and evaluations to ensure resilient and secure software supply chains.
Between 20% and 30% of some repositories9 code is AI-derived.
— Microsoft CEO
Agencies
U.S. Department of Defense, Defense Ministries
Vendors
Microsoft, GitHub Copilot, Claude Code, Lockheed Martin
Locations
Sources
- Your Defense Code Is Already AI-Generated. What Are the Next Steps? - DEFCROS News · news.defcros.com · Mar 25