Cybersecurity Research

Wiz Launches AI Code Scanner to Find Flaws Traditional Tools Miss

Wiz Research · 6 Oct 2026
Key Takeaway If your business builds or customises software, ask your developers or security provider how code is checked for flaws, and make sure findings are prioritised by what is actually exposed in production.

Wiz has announced Wiz AI SAST, now available as a Public Preview for all Wiz Code customers. The company says AI models have become highly capable at spotting complex flaws in application code that traditional, rules-based scanners often miss. Manual reviews and quarterly penetration tests have long filled that gap, but Wiz argues neither scales when code is written and exploited at machine speed.

According to Wiz, the tool analyses how an application actually behaves to uncover a wider range of weaknesses (known as CWEs). Findings are correlated with what is running in production through the Wiz Security Graph, so teams can see which issues matter most. Prioritised results feed into existing policy, ownership and remediation workflows rather than adding another tool to manage.

The tool is built on Atlas, a research initiative Wiz shared earlier this year. Wiz says Atlas held the top spot on CyberGym and uncovered more than 200 vulnerabilities in widely used open source software. The company also says that running AI code scanning in-house demands ongoing investment from skilled security and engineering teams, and that its product handles this out of the box. This is a vendor announcement, so these claims come from Wiz itself, and this summary covers only the opening of the article.

AI security SAST application security Wiz vulnerability management
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Wiz Research, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.