Friday, 11 September 2026 · Europe
EUR/USD 1.162 EUR/GBP 0.8591 EUR/CHF 0.9432 EUR/PLN 4.322 All rates →
Sign in · Join
EUROPES The European Report
European Edition Friday, 11 September 2026
LATEST 49ers beat Rams as 100,000 attend NFL Melbourne debut Le Flash →
Tech & Startups

AI tools enable staff to deploy vulnerable applications outside security checks

AI tools enable staff to deploy vulnerable applications outside security checks

The rise of AI coding assistants is allowing non-technical employees to build and publish internet-facing applications without security oversight, creating massive blind spots that threaten corporate infrastructure and investor confidence.

Artificial intelligence is enabling non-technical employees to build and publish internet-facing applications without passing through established security protocols. CyCognito chief executive Rob Gurzeev warns that this shift is creating vast, unmanaged blind spots across corporate networks.

“Today, anyone and everyone can deploy an app,” Gurzeev said. He noted that workers in departments like human resources or finance can use AI assistants such as Claude Code or Lovable to spin up software, exposing it to the internet on purpose or by accident.

The scale of this exposure is immense and poses a direct risk to corporate stability. Gurzeev estimates that a typical large enterprise now has around 100,000 applications, devices, and cloud assets visible to the internet, with some organizations having significantly larger footprints.

These external attack surfaces change by one to three percent every single day. Despite this rapid expansion, most corporate security programs remain focused on a small fraction of their environments. “Guarding the front door while you leave the windows open is not a strategy,” Gurzeev said.

The risk is compounded by the quality of the software being generated. Gurzeev points to research indicating that AI-written code introduces vulnerabilities at significantly higher rates than human-authored programming. “The honest answer is we’re defending more of something less safe, and we can’t yet measure exactly how much,” he said.

CyCognito attempts to solve this by mapping a company’s entire digital footprint from the outside in, starting with nothing more than a corporate name. Gurzeev, who began his career in intelligence reconnaissance, built the platform to validate what is actually exploitable rather than just scanning a known list of assets.

The company’s latest release combines full attack surface discovery with AI-powered validation to address this gap. The platform continuously performs more than 100,000 automated checks to handle known issues, freeing up artificial intelligence to identify complex attack chains that conventional scanners miss.

For European investors and corporate boards, the clear message is that periodic security assessments are no longer sufficient to protect business valuations. Gurzeev argues that the winners in this new landscape will be those who use computing resources efficiently with context, rather than simply spending the most money.

More from Tech & Startups