(DT05) (INCYBER) Développement assisté par IA – le coût caché de la vitesse

(DT05) (INCYBER) Développement assisté par IA – le coût caché de la vitesse

🎙 INCYBER 👥 7K 📅 April 9, 2026 ⏱ 25 min 👁 46 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

AI code generationvulnerabilitiessecure developmentLLMCheckmarx

Summary

The video is a presentation from the INCYBER Forum 2026, featuring Frédéric and Sophia from Checkmarx. They discuss the hidden costs of AI-assisted development, focusing on security risks. They start with an anecdote about a police report generated by AI that incorrectly stated an officer turned into a frog, illustrating AI’s lack of context. They then relate this to developers using AI coding assistants, who may push code to production without fully understanding it. They mention a trend from ‘vibe coding’ to ‘AI engineers’ who trust AI-generated code. They highlight vulnerabilities in tools like Claude Code, where a malicious file can exfiltrate data via session tokens. They also discuss the probabilistic nature of LLMs, leading to insecure patterns like hardcoded passwords. They reference benchmarks like BAXBENCH showing even top models produce vulnerable code. They argue that while AI accelerates development, it also accelerates the introduction of vulnerabilities, and current security tools are not keeping pace. They propose a solution involving governance and multiple checkpoints throughout the SDLC, including real-time scanning in the IDE, automated code review, and remediation guided by AI. They emphasize the importance of shifting left and extending governance to the developer environment. They conclude by inviting attendees to their booth for further discussion.

206 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the security challenges of AI-assisted development, using concrete examples and references to real incidents. The argumentation is coherent: they establish the problem (AI-generated code is often insecure), illustrate with examples, and propose a solution (integrated security checkpoints). However, the argumentation is somewhat biased as it promotes Checkmarx’s products, and the proposed solution is presented as the only viable approach. The technical depth is moderate, suitable for a professional audience but not highly technical.

Scientific Rigor, Source Quality, Title Accuracy

The presentation demonstrates scientific rigor by referencing specific incidents (e.g., the police report, Claude Code vulnerability) and benchmarks (BAXBENCH). However, detailed citations are not provided in the video, and the sources are not independently verified. The title accurately reflects the content, focusing on the hidden costs of AI-assisted development. The video is a promotional talk, which may affect objectivity, but the technical claims are plausible.

159 words

Title / Content Match

The title accurately reflects the content, which discusses the hidden costs of AI-assisted development, including security risks and productivity trade-offs.

Quality & Reliability

7/10

The presentation is given by security experts from Checkmarx, a recognized vendor in application security. It references real-world incidents (e.g., police report hallucination, Claude Code vulnerability) and benchmarks (e.g., BAXBENCH). However, it is largely promotional for Checkmarx's solutions, and some claims lack detailed citations. The technical explanations are plausible but not fully verifiable from the video alone.

Key Moments

Cited Sources

Concurring Sources

  • OWASP Top 10 — Referenced in the video as a source of common vulnerabilities

Contribution & Novelties

The video provides a practical perspective on the security implications of AI-assisted development, highlighting real-world examples and proposing a governance framework. It emphasizes the need for multiple checkpoints and real-time scanning in the IDE. The presentation is valuable for organizations adopting AI coding tools.

Pour aller plus loin :

81 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher scores in information quantity and quality, reflecting a well-structured but promotional presentation. The technical level is moderate, and reliability is average due to lack of detailed citations.

Reliability 6/10