The News
Checkmarx has announced Checkmarx Fusion, a hybrid scanning architecture now available in early access as part of the Checkmarx One platform. The product combines Checkmarx’s deterministic AppSec scanning engines with frontier AI reasoning powered by Anthropic’s Claude models via Amazon Bedrock, targeting what the company describes as the most complete vulnerability detection available across all languages and development stages. The announcement arrives as Checkmarx’s own research reports that 49% of production code is now AI-generated, a shift that the company argues has broken the economics of conventional single-approach vulnerability scanning.
Analyst Take
The AI-generated code problem is real, and the security toolchain hasn’t caught up
The 49% AI-generated code figure from Checkmarx’s own research is striking, but it tracks with a broader pattern ECI Research has been watching. ECI Research’s 2026 Application Development: DevSecOps & AppSec survey found that 45.3% of respondents said AI-assisted development has increased security risk moderately, with another 17.2% saying it has increased risk significantly. That’s nearly two-thirds of practitioners acknowledging that the same AI productivity wave driving code output is simultaneously degrading their security posture. Checkmarx Fusion is a direct product response to that dynamic. The pitch is architecturally coherent: use deterministic rules for the patterns you know, and use AI reasoning for everything the rules can’t reach, including novel languages, emergent attack surfaces, and the idiosyncratic constructs that AI code generators produce at scale.
Why the hybrid architecture matters more than the AI headline
The real technical differentiation here isn’t that Checkmarx bolted a large language model onto a scanner. It’s the architecture underneath. Running scanning workloads entirely within a customer’s own cloud environment via Amazon Bedrock means source code never transits Checkmarx’s or Anthropic’s infrastructure. For regulated industries, that’s not a nice-to-have. ECI Research’s 2026 Application Development: Day 1 survey found that 71.5% of respondents cited industry-specific compliance (FinServ/Healthcare) as a regulatory pressure influencing release engineering. That number goes a long way toward explaining why previous AI-powered security tooling has struggled to penetrate regulated verticals: the data residency problem was never solved at the architecture level. Checkmarx Fusion is targeting it by design rather than by policy exception.
The F1 score claim (0.741, described as nearly four times the category average) is the kind of benchmark that will draw scrutiny at Black Hat, and rightly so. Benchmark conditions in AppSec rarely reflect the messiness of real enterprise codebases. But the directional argument is sound: hybrid approaches that combine high-precision deterministic engines with AI-powered coverage extension should outperform either approach alone on both recall and precision, which is exactly what the F1 metric captures. ITDMs evaluating this product should ask vendors to run Fusion against their own repositories before committing, not against synthetic benchmarks.
The competitive stakes and what Checkmarx is actually defending
The competitive context matters here. Checkmarx is operating in a market where hyperscalers are embedding security tooling directly into developer workflows, and where point solutions from vendors have built strong developer followings on speed and low friction. Checkmarx Fusion is a bet that enterprise buyers will pay for integration depth and compliance architecture rather than defect to lighter-weight tools that lack the data residency guarantees and the two-decade vulnerability research corpus that Checkmarx brings. The model optionality (customers can select among Claude models to optimize cost and performance) is a shrewd concession to enterprise procurement realities: security budgets are under pressure, and a scanner that lets buyers tune the cost-performance tradeoff without losing coverage is a meaningful differentiator in competitive evaluations.
For developers, the practical implication is that Fusion should reduce the alert fatigue that has long undermined AppSec programs. If the false positive reduction claims hold in production, developers spend less time triaging noise and more time remediating real issues. That’s the actual workflow problem that has caused so many AppSec programs to stall.
Looking Ahead
The Checkmarx Fusion announcement signals a broader consolidation dynamic that will play out across the AppSec market over the next 12–18 months. Vendors that can credibly combine deterministic precision with AI-powered coverage extension, while solving the data residency problem for regulated buyers, will pull significantly ahead of those relying on either approach alone. Checkmarx’s early access timing ahead of Black Hat is calculated: the company is seeding enterprise evaluations before competitors can respond with comparable hybrid architectures, and the Anthropic partnership gives it a credible frontier model story without the infrastructure liability of running models in-house.
The harder question for Checkmarx is adoption velocity. Early access programs in AppSec have historically moved slowly because security tooling changes require extensive validation before production deployment, and because organizational change management in security teams is genuinely difficult. The real test of Fusion’s market impact won’t come from the Black Hat booth; it will come from whether enterprise customers running it in early access convert to full production deployments by mid-2027 and whether the false positive reduction holds at scale across heterogeneous codebases.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
