The same AI models generating code are also best at exploiting it, creating a dual-use problem for security. Independent verification layers outside the generator’s control are necessary for trustworthy code review rather than relying on self-attestation.