AI Code Assistants and Security API Usage: Empirical Study

44 developers participated in a study on GitHub Copilot's impact on security API usage. Findings show Copilot fails to enhance secure API usage.

martes, 28 de julio de 2026 • 3 min read • Q2BSTUDIO Team

Asistentes de IA: impacto limitado en la seguridad de APIs

The rise of artificial intelligence assistants in software development has sparked a deep debate about their impact on application security. A recent empirical study presented on arXiv (2607.11348v1) sheds light on how tools like GitHub Copilot affect professional developers' use of security APIs. This analysis is crucial for companies seeking to balance productivity and protection in environments where cybersecurity is a priority. At Q2BSTUDIO, as a company specialized in software development and technology, we understand that integrating AI must be accompanied by solid strategies to ensure that custom software is not only functional but also secure.

The study, conducted with 44 developers, evaluated programming tasks with security APIs, comparing performance with and without Copilot assistance. The results reveal that, although the assistant improves functional correctness and reduces certain insecure patterns, it does not achieve a significant improvement in the secure use of these critical APIs. This underscores a reality: AI assistants can accelerate processes but do not replace human judgment or deep cybersecurity knowledge. For organizations adopting cloud AWS/Azure, this finding is especially relevant, as incorrect configuration of security APIs in the cloud can expose sensitive data.

One of the most concerning observations is that developers rarely raise security concerns when interacting with Copilot, and many do not recognize that their final implementations remain insecure. This indicates that AI, by itself, does not educate or alert about vulnerabilities. At Q2BSTUDIO, we combine AI agents with human review processes to ensure that every line of code meets security standards. Our cybersecurity services include pentesting and audits that complement the use of intelligent assistants, detecting flaws that these tools overlook.

The study also highlights that the inherent complexity of security APIs—such as authentication, encryption, or access control—remains a barrier. AI assistants offer suggestions but do not contextualize domain-specific risks. For example, when implementing OAuth 2.0 or JWT, an inexperienced developer may accept a recommendation that works functionally but introduces vulnerabilities like token exposure or lack of validation. To mitigate this, companies must invest in continuous training and automation solutions that integrate security controls into the development pipeline.

From a technical perspective, the study recommends improving security awareness among developers. This includes incorporating contextual alerts in AI assistants and fostering collaborative code reviews. At Q2BSTUDIO, we develop custom applications that integrate BI/Power BI dashboards to monitor security metrics in real-time, allowing detection of anomalies before they become incidents. Additionally, our cloud AWS/Azure solutions are designed with secure-by-default architectures, minimizing exclusive reliance on AI tools.

The future of AI-assisted development requires a balance between efficiency and responsibility. Companies adopting these technologies must establish clear policies: use assistants as support, not as final authority; train teams in cybersecurity fundamentals; and conduct periodic audits. At Q2BSTUDIO, we offer digital transformation consulting where we assess the maturity of your processes and help you implement secure practices without sacrificing delivery speed. Our team combines expertise in software development, artificial intelligence, and cybersecurity to ensure your projects are robust and reliable.

In conclusion, the empirical study analyzed confirms that AI assistants, while powerful, are not a magic solution for API security. Organizations must complement them with human and technical strategies. At Q2BSTUDIO, we are committed to providing custom software that integrates AI securely, protecting your digital assets in an increasingly complex environment. Contact us to discover how we can help you build technology with confidence.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.