Skip to content

Executive Summary

AI coding agents frequently produce authorization logic that violates security policies, which is a major concern given that broken access control ranks first in the OWASP Top 10. This vulnerability category includes Broken Object-Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR), which occur when an application fails to verify if an authenticated user is entitled to the specific data they request. The difficulty arises because AI agents operate without inherent knowledge of application-specific business rules, such as data ownership boundaries, which are external facts not present in the code itself. While static analysis excels at detecting pattern-based vulnerabilities like path traversal, object-level authorization resists traditional signature matching. Addressing this requires moving beyond simple pattern matching to incorporating an application-context graph that models data flow, trust boundaries, and business rules.

Facts Only

* Broken access control ranks first in the OWASP Top 10:2025, with 100% of tested applications showing some form of it.
* Broken access control includes BOLA (broken object-level authorization) and IDOR (insecure direct object reference).
* BOLA is the failure to verify that a requester is entitled to a specific requested object.
* IDOR is exposing internal identifiers, allowing substitution to return data belonging to another account.
* The AI agent's generated code often follows correct procedural steps but misses necessary application-specific authorization checks.
* Authorization requirements are often unstated in prompts, leading agents to generate functional but insecure endpoints.
* Object-level authorization is resistant to pattern-based scanning because it depends on contextual knowledge (e.g., ownership rules).
* Static analysis handles pattern-based vulnerabilities well, but object-level authorization requires understanding the application's internal data model and access rules.
* Finding flaws that lack patterns requires reasoning over an assembled application context graph.

Full Take

The issue with AI agents writing authorization logic stems from a fundamental gap: code generation is procedural, while authorization enforcement is contextual, residing in unstated business reality. The agent can execute the requested steps correctly—verifying authentication and handling errors—but lacks the necessary context regarding who should be allowed to access which specific resource. This forces security tooling to evolve from signature-based scanning to reasoning over an assembled application context graph, integrating architectural knowledge, data flows, and trust boundaries. The proposed solution involves grounding AI analysis not just in the code structure but in a holistic model of the application's operational reality—facts like ownership schemas—and validating results through comprehensive functional testing that tests cross-tenant access explicitly. This shifts the focus from merely finding patterns to reasoning about structural necessity, recognizing that security enforcement is less about syntactic pattern matching and more about modeling dynamic relationships within a system.

From the original · Snyk Blog

October 1, 2026 0 mins readAI coding agents produce authorization logic that compiles, passes review, and enforces the wrong policy. Broken access control ranks first in the OWASP Top 10:2025, where 100% of applications tested showed some form of it, across 1,839,701 recorded occurrences, the highest count of any category on the list.
Read the full story at snyk.io

Sentinel — Human

Confidence

This analysis synthesizes known security concepts with a novel argument about the inadequacy of pattern-based AI code scanning for authorization flaws, relying on structured reasoning rather than simple aggregation.

Signals Detected
low severity: Sentence length variance is natural; sophisticated vocabulary is used, but the flow has a distinct argumentative arc.
low severity: The argument flows logically from identifying a problem (broken access control in AI code) to defining it, explaining why agents fail, detailing the necessary context, and proposing solutions. It possesses an idiosyncratic emphasis on the missing 'context'.
low severity: The structure follows a typical high-level analytical essay format, introducing concepts (BOLA/IDOR), building a central thesis about context dependency, and listing actionable steps. This pattern is common in expert technical writing.
low severity: The text discusses specific OWASP rankings and cites research/tools (OWASP, Snyk, Evo), which suggests grounding in existing domain knowledge, although the novel synthesis of these ideas is highly specific.
Human Indicators
The text employs a sophisticated argumentative structure that prioritizes reasoning over mere data recitation, focusing heavily on the gap between automated pattern matching and contextual security requirements.
The advice provided is highly actionable and reflects an understanding of the practical pain points in the SDLC (developer vs. agent).
There is a distinct voice emphasizing *why* certain information is missing rather than just stating the facts, which suggests human insight guiding the exposition.
Why AI Coding Agents Keep Writing Broken Access Control | Huntaegis