The AI coding assistants your developers use every day could leak company secrets, take actions without accountability, and rack up costs without oversight.
The scale of adoption makes these risks an executive-level concern: 90% of developers regularly use at least one AI tool at work for coding and development tasks. What sets AI coding assistants apart from traditional developer tools is their combination of broad access to company systems and information with the ability to act autonomously.
“Many of the board discussions are around needing more AI adoption. And that’s great, because it does provide significant productivity gains,” said Gunjan Patel, Senior Direct of Product Management for AI Security at Palo Alto Networks. “But the other side is security risk and financial risk. AI agents have a mind of their own, they can do whatever they want, and often have the same level of access as your employees—but without any accountability.”
For business leaders, three areas deserve particular attention: intellectual property (IP) exposure, unsanctioned activity and unchecked spend.
Exposing sensitive IP
AI coding assistants need access to sensitive company information, from source code and credentials to customer data. But their ability to pull in external tools and skills can also create a path for that information to leave the organization.
The risk is already showing up in public code. GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits in 2025, up 34% year over year. Claude Code-assisted commits showed a 3.2% secret-leak rate, more than twice the 1.5% baseline across public GitHub commits.
When credentials are exposed, the risk can extend beyond the information itself by giving attackers a way into company systems.
“You’re not just risking the loss of sensitive information. You could be putting your entire enterprise at risk. For example, if a key is leaked and someone gets access to it, they could potentially bring down the company’s systems,” noted Patel.
Acting without accountability
AI coding assistants can operate continuously, with broad permissions and limited human oversight. They typically assume the developer’s identity, which means hundreds of agents could be running with identical credentials.
It’s a perfect storm for unsanctioned activity. When something goes wrong, organizations may struggle to determine what happened, which assistant was responsible, and why it took the action—with consequences including liability and regulatory exposure.
“There are cases in the news where a model was so capable that the AI agents formed a swarm, worked together, and broke out of a secure sandbox before hacking another company. They acted autonomously, without humans realizing what happened until after the fact,” said Patel. “In that test case scenario, there was no financial damage. But imagine if you were on the receiving end of that type of activity in a real scenario, or if your AI coding agents did that to another company. There can be serious consequences and reputational damage to consider.”
Losing control of costs
Another area that can quickly become difficult to control is token spend. Long context windows, autonomous workflows and repeated loops can consume tokens rapidly, multiplied across thousands of AI coding assistants.
When the bill climbs, organizations may not know why: Which team is driving the increase? Which coding assistant? Which model?
“Spend can get out of control very fast,” Patel said. “Token cost can double or even triple month over month. And it’s extremely unpredictable compared to all the other costs, due to the nature of agents being non-deterministic.”
Gartner predicts AI coding costs will surpass the average developer’s salary by 2028 as token consumption surges, making visibility into usage and spend urgent.
Traditional security wasn’t designed for AI coding assistants
AI coding assistants introduce new attack paths that can slip through traditional security defenses.
In a recent “Agentjacking” test, for example, researchers planted malicious instructions in fake Sentry error reports that AI coding agents retrieved and executed using developers’ privileges. The attack bypassed endpoint detection and response (EDR), identity and access management (IAM), virtual private network (VPN), web application firewall (WAF) and firewall controls because the actions appeared authorized. It achieved an 85% success rate in testing across more than 100 organizations.
In this environment, one of the most essential security measures is an AI gateway, which is a control point that sits between the coding assistant and all the models, tools and external services it interacts with.
The gateway lets organizations see what coding assistants connect to and what information they share, control what leaves the company and block policy violations. It also traces agent activity and tracks token consumption and cost.
“Organizations can absolutely take a phased approach to securing AI coding assistants,” Patel said. “Start with an AI gateway, and then build the other security systems on top of that. The gateway is key because it acts as the crucial checkpoint on what is now the ‘information highway’ for AI-assisted coding.”
What boards should be asking
As boards encourage greater AI adoption and productivity, they also need to hold their organizations accountable for security and cost control. That starts with asking the right questions:
- What’s in our environment? How many sanctioned and unsanctioned AI coding assistants are developers using?
- Are we protecting company information? Can we see and stop sensitive information from leaving the organization?
- Can we trace what agents do? If something goes wrong, can we tell whether a developer or AI assistant took the action?
- Do we have control over AI spend? Do we know which assistants, models and teams are driving token usage, and do we have budget controls?
The opportunity for boards is to ask these questions now, before gaps in oversight become business consequences.
To learn how to secure and govern AI coding agents across your organization, visit www.paloaltonetworks.com/secure-ai-coding.
Read more about Palo Alto Networks’ approach to securing AI coding agents by downloading the AI Coding Security solution brief.





