Signal

A 1.1 million-post study says AI coding assistants fail developers on security and privacy — by default, not by exception

Researchers from York University and the University of Calgary mined 1.1 million Reddit posts and built a taxonomy of security and privacy failures in AI coding assistants like Claude Code, Cursor, GitHub Copilot and Replit — and the single biggest issue, at 43% of security complaints, is unauthorised file operations.