Ninety‑five percent of organizations report AI capabilities in their mobile applications, according to a NowSecure analysis — a figure that places artificial intelligence at the center of modern mobile functionality even as security controls lag behind.
How AI shows up in mobile apps
NowSecure’s recent report found that generative AI is the most common AI use case in mobile applications, present in 81% of organizations’ apps, and AI agents appear in 71%. The survey also reports that 74% of organizations say they have a formal AI governance policy. Despite those governance numbers, however, 37% of organizations have not implemented AI behavioral monitoring as a security control — a gap the report highlights between policy and operational safeguards.
Heavy dependence on third‑party SDKs and libraries
Sixty‑eight percent of surveyed organizations report that more than half of their mobile application code consists of third‑party software development kits (SDKs) and libraries. NowSecure frames this reliance as consequential: many enterprises are deploying apps built mostly with third‑party code that “may not have been fully assessed before deployment.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble →Third‑party code correlates with higher incident rates
The report links the extent of third‑party code in an app with security outcomes. Organizations whose apps contain more than 50% third‑party code experienced security incidents at more than double the rate of organizations whose apps contain less than 50% third‑party code. That statistical relationship is presented as a clear association in the report.
SDK assessment practices and attack surface management
Only 49% of organizations say they always assess SDKs for security or AI‑related risks before release. NowSecure notes that mobile security leaders increasingly identify SDKs and partner integrations as among the most difficult parts of the attack surface to manage. Put together, the findings underline two simultaneous realities: wide adoption of AI features and persistent challenges in evaluating the security posture of embedded third‑party components.
What this means for technologists, procurement leaders, and mobile security leaders
- Technologists and security teams: a large majority of apps include AI features (95%), and generative AI is especially common (81%). Yet 37% of organizations lack AI behavioral monitoring — a detail security teams will need to account for when prioritizing controls.
- Procurement and release managers: 68% of organizations report that third‑party code makes up more than half of their mobile apps, while only 49% always assess SDKs pre‑release. Those figures put integration and pre‑deployment assessment squarely in procurement and release workflows.
- Mobile security leaders: the report says these leaders are increasingly flagging SDKs and partner integrations as among the hardest parts of the attack surface to manage, and apps with heavy third‑party composition show more than double the incident rate compared with apps that do not.
The NowSecure analysis paints a picture of rapid AI uptake inside mobile apps paired with uneven operational security practices. High prevalence of generative AI and AI agents, broad reliance on third‑party SDKs, and measurable correlations between third‑party code and incident rates are the concrete findings the report delivers — and they leave a single clear question for organizations building and deploying mobile software: are governance statements being translated into the technical controls and supply‑chain checks the report identifies as critical?
Read the original report summary: https://www.securitymagazine.com/articles/102459-mobile-application-security-fails-to-match-levels-of-ai-use




