AI is writing more code and pulling in more dependencies, increasing application risk. Most of that exposure isn’t from code your team actively chose. A 2025 study of the Maven ecosystem found vulnerabilities reaching roughly 63% of latest releases through transitive dependencies, versus 31% through direct ones.