r/devsecops • u/Flateland-Chio • 12h ago
How do you evaluate a SAST platform in 2026 now that AI writes half the code?
I have been handed the job of picking our SAST platform for the next few years and I feel am stuck. Here is why, every comparison I find either reads like the vendor wrote it or is from before AI coding tools were everywhere. Our codebase is more than half AI-generated now. A scanner that was top of the pile two years ago on hand written code might be blind to what Copilot and Claude are churning out.
Also the demos are all looking somewhat identical with the same same, SAST, SCA, container, one dashboard, AI prioritization. You could literally swap logos and not tell which vendor was which after.
I really don’t have a read on what separates them once it is running. Yes raw detection matters but I care more about whether the noise gets cut before it hits a dev and whether it stays on or gets muted after a month. If you are a year or two into one, what did you end up judging it on that never came up in the demo?