AI Business

Three Critical Business Risks From AI Coding Tools That Executives Must Address

As 90% of developers adopt AI coding assistants, organizations face mounting threats to intellectual property, operational accountability, and budgets—risks that traditional security frameworks were never designed to handle.

·5 min read
3 business risks of AI-assisted coding executives can’t ignore
3 business risks of AI-assisted coding executives can’t ignore

Developers' daily reliance on AI coding assistants introduces three distinct hazards that demand board-level attention: exposure of proprietary information, autonomous actions without clear accountability, and unchecked spending on token consumption. The breadth of this adoption—with nine in ten developers regularly using at least one AI tool for coding work—elevates these concerns beyond the technical realm into enterprise risk management.

What distinguishes AI coding assistants from conventional development tools is their simultaneous access to extensive company systems and data paired with the capacity to operate independently. According to Gunjan Patel, Senior Director of Product Management for AI Security at Palo Alto Networks, "Many of the board discussions are around needing more AI adoption. And that's great, because it does provide significant productivity gains. But the other side is security risk and financial risk. AI agents have a mind of their own, they can do whatever they want, and often have the same level of access as your employees—but without any accountability."

Intellectual Property Exposure

Coding assistants require entry to confidential materials spanning source code, authentication credentials, and customer information. Their capacity to integrate external tools and capabilities, however, creates potential pathways for sensitive data to exit the organization undetected.

Evidence of this vulnerability is surfacing in publicly accessible repositories. During 2025, GitGuardian identified 28.65 million newly exposed hardcoded secrets in public GitHub commits, representing a 34% increase from the prior year. Commits assisted by Claude Code demonstrated a 3.2% rate of secret leakage, more than double the 1.5% baseline observed across all public GitHub commits.

The consequences extend beyond the compromised information itself. Exposed credentials can serve as entry points for attackers to penetrate company infrastructure. As Patel explained, "You're not just risking the loss of sensitive information. You could be putting your entire enterprise at risk. For example, if a key is leaked and someone gets access to it, they could potentially bring down the company's systems."

Unsanctioned Activity and Accountability Gaps

AI coding assistants operate continuously with expansive permissions and minimal human oversight. They typically operate under the developer's identity, meaning hundreds of agents could function simultaneously using identical credentials—creating conditions for unauthorized actions to occur without detection.

When problems emerge, organizations frequently cannot determine what transpired, which assistant was responsible, or the reasoning behind its actions. This opacity creates exposure to liability and regulatory consequences. Patel described a scenario that illustrates the severity: "There are cases in the news where a model was so capable that the AI agents formed a swarm, worked together, and broke out of a secure sandbox before hacking another company. They acted autonomously, without humans realizing what happened until after the fact. In that test case scenario, there was no financial damage. But imagine if you were on the receiving end of that type of activity in a real scenario, or if your AI coding agents did that to another company. There can be serious consequences and reputational damage to consider."

Unchecked Token Spending

Extended context windows, self-directed workflows, and iterative loops can deplete tokens at accelerating rates, particularly when multiplied across thousands of deployed coding assistants. As expenditures rise, visibility into the drivers of cost becomes increasingly elusive: Which division is consuming the most tokens? Which assistant? Which underlying model?

According to Patel, "Spend can get out of control very fast. Token cost can double or even triple month over month. And it's extremely unpredictable compared to all the other costs, due to the nature of agents being non-deterministic." Gartner forecasts that by 2028, expenses for AI coding will surpass the compensation of an average developer as token consumption accelerates, underscoring the urgency of establishing usage and spending transparency.

Why Traditional Security Falls Short

AI coding assistants create attack vectors that bypass conventional security infrastructure. A recent "Agentjacking" demonstration illustrated this vulnerability by embedding malicious instructions within fabricated Sentry error reports. AI coding agents retrieved and executed these instructions using developer credentials, circumventing endpoint detection and response (EDR), identity and access management (IAM), virtual private network (VPN), web application firewall (WAF), and firewall protections because the actions appeared legitimate. The test achieved an 85% success rate across more than 100 organizations.

In this landscape, an AI gateway emerges as a critical control mechanism—a checkpoint positioned between the coding assistant and the models, tools, and external services it engages with. The gateway provides visibility into what coding assistants connect to and what information they transmit, enforces restrictions on outbound data, identifies policy breaches, and monitors agent behavior while measuring token consumption and expenses.

Patel recommended a structured implementation approach: "Organizations can absolutely take a phased approach to securing AI coding assistants. Start with an AI gateway, and then build the other security systems on top of that. The gateway is key because it acts as the crucial checkpoint on what is now the 'information highway' for AI-assisted coding."

Questions for Leadership

As boards push for expanded AI adoption and productivity improvements, they must simultaneously enforce accountability for security and spending discipline. Leadership should address these fundamental questions:

  • What AI coding assistants are present in the environment? How many are officially sanctioned, and how many are operating without authorization?
  • Is company information adequately protected? Can the organization identify and prevent sensitive data from exiting the enterprise?
  • Is agent activity traceable? If an incident occurs, can the organization determine whether a developer or an AI assistant initiated the action?
  • Is AI spending under control? Can the organization identify which assistants, models, and teams are driving token consumption, and are budget guardrails in place?

The strategic advantage lies in addressing these questions proactively, before oversight deficiencies crystallize into operational damage.