I Need IT Support Now
Managed IT Houston
Shane

Microsoft AI Now Generates 20-30% of Internal Code: What This Means for Business Technology

When machines write code, you need human expertise. You need CinchOps – AI is writing Microsoft’s Future

AI & Software
Microsoft Says AI Writes Up to 30% of Its Code. "Written by AI" Is Not the Same as "Safe to Ship."

Satya Nadella and Sundar Pichai put real numbers on AI coding. Here is what is genuine, what is hype, and the security risk businesses need to know.

TL;DR
Microsoft CEO Satya Nadella says AI now writes roughly 20-30% of the company's internal code, and Google's Sundar Pichai reports over 30% at Google - with Meta aiming for about half of its development within a year. Microsoft's CTO has floated 95% of code being AI-generated by 2030. The catch: results vary by language (Python "fantastic," C++ "not that great"), and AI models regularly invent package names that do not exist - a supply-chain risk called slopsquatting, where attackers register the fake names and publish malware. AI coding is real and useful, but it raises the value of human review, not lowers it. For businesses adopting it, security-first oversight is the whole game.

AI now writes a meaningful share of Big Tech's code - but the same tools regularly invent software packages that do not exist, creating a real security risk.

Speaking with Meta's Mark Zuckerberg at the LlamaCon conference, Satya Nadella said "maybe 20%, 30% of the code that is inside of our repos today... [is] probably all written by software." It is a striking milestone - and an easy one to misread. The gap between "AI can write code" and "AI-written code is safe to run" is exactly where businesses get into trouble. This is a look at what the numbers really say, and the security reality behind the headline.

The core point: the more code your tools generate, the more your advantage comes from how well you review it. AI raises the value of good oversight - it does not remove the need for it.

What's Actually Happening

The numbers, straight from the executives.

Microsoft reports 20-30% of its code is AI-written, Google over 30%, and Meta wants AI doing about half its development within a year.

The disclosures came fast: Nadella's 20-30% for Microsoft, Sundar Pichai's report of more than 30% at Google, and Zuckerberg's goal of AI handling roughly half of Meta's development in the coming year. Microsoft CTO Kevin Scott has gone further, suggesting 95% of all code could be AI-generated by 2030. But the results are uneven. Nadella called AI's Python output "fantastic" while describing C++ as "not that great" - a reminder that AI coding quality still depends heavily on the language and the task. Python's simpler syntax and automatic memory management suit AI far better than C++'s complexity and manual memory control.

Myth vs Fact: Cutting Through the Hype

The headline invites some dangerous assumptions.

Most of what goes wrong with AI coding comes from treating a productivity tool as a finished, trustworthy engineer.

The mythThe reality
"If AI writes a third of Big Tech's code, it can run our development."Those companies still have expert engineers reviewing everything. AI assists; it does not replace human judgment.
"AI-generated code is ready to ship."Research found AI suggested non-existent software packages in roughly 20% of cases - opening a supply-chain risk called slopsquatting.
"AI writes every language equally well."Nadella called Python results "fantastic" but C++ "not that great." Quality varies sharply by language and task.
"AI coding makes developers obsolete."The valued skills shift to architecture, code review, security, and prompt engineering - human oversight matters more, not less.
"More AI code automatically means fewer bugs."Only with review. Unreviewed AI code can introduce vulnerabilities faster than a human team would.

The AI-coding hype, and what the evidence actually shows.

The slopsquatting risk deserves a closer look. When an AI tool confidently recommends a package that does not exist, an attacker can register that exact name in a public registry like npm or PyPI and publish malware under it. The next developer who trusts the suggestion installs attacker-controlled code. Because models tend to repeat the same made-up names, attackers can find viable targets by watching just a handful of outputs. That is not a reason to avoid AI coding - it is a reason to verify every dependency it suggests.

What It Means for Your Business

Real upside, on the condition you keep control.

AI coding can speed delivery and shift your team toward higher-value work - but only inside a security-first process.

  • Faster delivery. AI assistants can cut development time for routine work, speeding new applications and features to market.
  • Higher-value roles. As AI handles boilerplate, your people move toward architecture, code review, security, and prompt engineering.
  • Wider participation. AI lowers the barrier so more of your team can contribute to technical projects - with guardrails.
  • Consistency, with a catch. Well-guided AI can produce steady, readable code - but only human review keeps that consistency from including consistent mistakes.
  • Security is the gate. Dependency verification, scanning, and human review are what turn AI-generated code from a liability into an advantage.

Adopting AI Coding Tools? Do It Safely.

CinchOps helps businesses put AI development tools to work with the review, dependency checks, and security guardrails that keep AI-generated code from becoming an open door.

Talk to CinchOps
100% Free

Free Cybersecurity Assessment

Using AI coding tools without a security process? Get a FREE assessment of how your development and dependencies are protected.

Get Your Free Assessment

The 20-30% number is not the risk. The risk is a business reading it as permission to skip review. AI writing more of your code makes human oversight more valuable, not less - especially when the tool can confidently invent a package that a malicious actor is waiting to register.
Shane Stevens, CEO, CinchOps - LinkedIn

Put AI to Work Without the Security Debt

CinchOps helps you adopt AI development tools with dependency verification, code security review, and team training - as part of everyday managed IT and cybersecurity.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, helping you adopt AI development safely.

  • AI implementation strategy. Deciding where AI coding tools fit your workflow to gain speed without losing control.
  • Code security review. Checking AI-generated code and its dependencies for the vulnerabilities and invented packages models introduce.
  • Developer training. Building the review, prompting, and security skills your team needs to work alongside AI.
  • Custom AI integration. Connecting AI assistants to your existing environment with the right guardrails.
  • Security-first development. Embedding dependency verification and scanning into the way your team builds.

Adopt AI coding without the hidden risk. Contact CinchOps to build a safe, productive AI development process.

Frequently Asked Questions

How much of Microsoft's code is written by AI?

Microsoft CEO Satya Nadella said roughly 20-30% of the company's internal code is now AI-written. Google's Sundar Pichai has reported over 30% at Google, and Meta's Mark Zuckerberg set a goal of AI handling about half of Meta's development within a year.

Is AI-generated code safe to use?

Only with human review. AI models regularly suggest software packages that do not exist and can introduce vulnerabilities. Research found AI recommended non-existent packages in roughly 20% of cases. AI-generated code should always be reviewed, scanned, and dependency-checked before it ships.

What is slopsquatting?

Slopsquatting is a supply-chain attack that exploits AI "hallucinations." When an AI tool repeatedly recommends a package name that does not exist, an attacker registers that name in a public registry like npm or PyPI and publishes malware. Developers who trust the AI suggestion then install the malicious package.

Will AI replace software developers?

Not in the way the hype suggests. AI is automating routine coding, but the skills that gain value are architecture, code review, security assessment, and prompt engineering. Human oversight becomes more important as more code is machine-generated, not less.

How should a business adopt AI coding tools safely?

Treat AI as an assistant, not a replacement. Verify every dependency it suggests, scan generated code for vulnerabilities, keep human review in the loop, and train developers on secure AI use. A managed IT and security partner can build these guardrails into your workflow.

Discover More

Sources

Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including senior roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506