AppSec spend to near $13bn by 2031 as vibe coding lifts demand

Juniper Research forecasts 16% growth in enterprise application security spending by 2031, driven by AI-assisted coding risks.

A silver cylindrical device and a circuit board with copper heatsinks and black components rest on a blue mat on a bright white laboratory tabletop.

Enterprise spending on application security is on course to approach $13 billion globally by 2031, up from $11 billion in 2026, according to new research from Juniper Research. The Hampshire-based analyst firm projects compound growth of over 16% across the five-year period, attributing the acceleration primarily to the proliferation of AI-assisted software development and the vulnerabilities it introduces.

The report, Application Security Market 2026-2031, singles out "vibe coding" as the central threat reshaping the sector. Vibe coding refers to the practice of using AI models to generate or co-write code at high speed, often with limited manual review. Juniper's analysis concludes that legacy scan-and-report AppSec tooling cannot handle the volume or velocity of code produced this way, creating a gap that purpose-built, AI-aware platforms are positioned to fill.

The vibe coding threat

Thomas Wilson, the report's author, described the scale of the shift: "Vibe coding will shift AppSec from securing a relatively controlled development pipeline, to continuously securing a much larger and faster-moving volume of AI-generated code; making automation and security-by-design increasingly critical."

The research argues that enterprises should resist the temptation to restrict AI coding tools outright, and instead prioritise investment in security platforms capable of identifying vulnerabilities earlier in the development lifecycle. Overlooked dependencies and insecure defaults are cited as the most common failure modes in AI-generated codebases.

Juniper also published a Competitor Leaderboard for AppSec vendors as part of the study. The three firms ranked as established leaders are Veracode, Checkmarx and Black Duck. The report credits all three with broad portfolio coverage, automated vulnerability detection and integration across the software development lifecycle, attributes it considers prerequisites for enterprise buyers managing increasingly complex, AI-accelerated codebases.

Market context

The AppSec category is itself in transition. For much of the last decade, the dominant model involved periodic static and dynamic analysis scans followed by remediation backlogs, a workflow poorly suited to continuous deployment pipelines. The rise of DevSecOps has already pushed vendors toward real-time pipeline integration, and the vibe coding phenomenon adds further pressure by expanding the attack surface faster than most security teams can manually triage.

Veracode, Checkmarx and Black Duck each entered this cycle with established enterprise customer bases and scanner-led revenues, but have moved to platform and API-first models to remain relevant in cloud-native environments. A growing set of challengers, including pure-play AI security startups and broader cloud-native application protection platform vendors, are competing for the same buyers by emphasising agent-based runtime detection and automated remediation, capabilities that legacy scanner vendors are now racing to add.

Regulatory tailwinds are also material. The EU Cyber Resilience Act, which entered into force in 2024 and phases in mandatory software security requirements through 2027, obliges manufacturers of products with digital elements to conduct vulnerability assessments and maintain software bills of materials. In the US, CISA's Secure-by-Design guidance and the White House's National Cybersecurity Strategy place similar expectations on software producers. Both regimes increase the compliance cost of inadequate AppSec tooling and should serve as a structural driver of the spending growth Juniper forecasts.

The full Juniper dataset covers forecasts for over 70 countries and contains more than 43,000 market statistics across the five-year window. A free extract focused on the vibe coding threat is available via the firm's website.