62% of Security Leaders Say AI Code Risk Is Now Urgent

/ $7M bet says most companies aren't ready.

Published: August 12, 2026 at 5:49 AM EDT
Image : Stephanie Smith / TheTweaks
Cytix
Image : Stephanie Smith / TheTweaks

AI Code Is Being Written Faster Than It’s Being Watched. And That’s What Makes The New $7 Million Series A Round Of Funding From Cytix Significant

Northern Gritstone led the investment in the UK based Cytix AI Security Inc with backing from existing investors Auriga Cyber Ventures and NPIF II PXN Equity Finance (through the Northern Powerhouse Investment Fund II). But what should draw our attention is the percentage from Cytix’s own presentation: only 38% of security leaders think their organization is ready for the amount of AI generated code entering their systems.

Here is why the latter is the unique thing to focus on and not the former.

The Main AI Code Security Issue Is Not Bugs, It’s Blind Spot

The majority of cyber security tools answer one thing: is the code vulnerable or not. Which is good and important. But now when AI coding assistants, agentic development workflow and continuous delivery processes increase the amount of code changes at a speed that nobody could imagine, the main question shifts to another one.

Now it is not about “is the code vulnerable”. Now it is about “how much business risk it poses”.

The team at Cytix says the issue is in the gap between vulnerability detection and business risk visibility. Security teams can provide endless scan reports to CISOs. But what they cannot do is say to CISOs “this particular change that we did using AI made our organization more exposed”.(Tech.eu)

Why It Is Happening Right Now

It is not a coincidence. In a relatively short period, AI assisted coding tools have become a standard. And with that came a lot of code changes.

Cytix shares the results of research saying 62% of security leaders think risk within their organization is moving from something latent and manageable to something immediate and active. When combined with the 38% “prepared” figure, we get a picture: the majority of security leaders already feels the ground under them is shaking, but only few of them feel they are ready to handle it.

That is the target market Cytix is going after not “we can detect more bugs” but “we will tell which of your AI driven changes really matter”.

How Does Cytix’s Platform Work?

Unlike other scanners, Cytix’s platform is not another layer in the development pipeline. The company positions it as a control layer between engineering teams and risk, compliance and security functions that are responsible for what will be shipped.

It works in 4 steps:

  • Continuous monitoring – tracking every single change to the software.
  • Risk analysis – evaluating the business risk posed by this particular change.
  • Response determination – deciding what action is needed to be taken if there is a risk.
  • Verification and evidence – proving the risk is really mitigated and providing a record of the process.

That last step is essential. In regulated industries – finance, healthcare and critical infrastructure – ability to provide evidence how the risky change was managed, not just how it was fixed, is the difference between passing an audit and getting a violation.

Enterprise First Approach, Not Start-Up-First

Cytix is not targeting developer tools market as a whole. And the funds it received during the Series A round are meant to be spent on scaling into large enterprises and regulated sectors. Because in such industries “software change governance” is not a feature, it is a mandatory part of the regulatory framework.

To enter such markets faster, Cytix has created go to market partnerships with NCC Group and KPMG, two known names in enterprise security and risk consulting market. This is a smart move from the point of view of Series A company borrowing reputation and distribution from the firms that already have relationships with such companies.

TheTweaks Verdict

Funding rounds are easy to skip over another cybersecurity start-up, another single digit million, another “AI risk” pitch deck. But when we strip away the round size and look at the statistics Cytix presents, we see that the company is targeting something that is seriously underserved.

The 38% preparedness stat is the number worth keeping in mind, not $7 million. It means that currently most enterprises are flying almost blindly because of the acceleration of the code changes driven by AI tools and next generation of security spending won’t be about finding more bugs but about knowing which changes actually matter before they are shipped.

Whether Cytix will be able to become a leader in “change risk management” category is an open question. But the issue it is chasing is genuine and it will only grow as AI generated code becomes standard instead of an exception.

For more AI and tech news, visit TheTweaks AI News or check out our latest tech launches and big tech coverage. 

Most Related