
NowSecure’s 2026 Mobile App Risk Management Survey of 485 mobile security leaders finds AI is embedded in apps faster than governance can follow: 95% report AI capabilities, with generative AI at 81% and AI agents at 71%, yet 37% have not implemented AI behavioral monitoring. Third-party code dominates—68% say more than half their app code is third-party SDKs/libraries—where apps with >50% third-party code see security incidents at over double the rate, while only 49% always assess SDK/AI risks before release. The survey also suggests organizations may be overestimating security program maturity, with AI tools (Claude Sonnet, ChatGPT, Gemini) predicting up to ~60 percentage points lower confidence on internal readiness/monitoring items.
This reads less like a near-term demand surge and more like evidence that mobile security budgets are shifting from static scanning toward runtime telemetry, AI policy enforcement, and third-party dependency mapping. The beneficiaries are the vendors that can prove what is actually shipped and executed, not the ones selling checklist governance; that favors broader platform security names with data exhaust and policy enforcement, while point tools built around pre-release review face slower renewal expansion.
Second-order effect: the biggest operational pain is not AI itself but the combinatorial risk of SDK sprawl plus AI-enabled code paths, which pushes security teams to buy around software composition analysis, mobile app testing, and supply-chain attestation. That should help adjacent categories in application security and zero trust, but the spending may be fragmented because mobile teams, app owners, and security governance all control different parts of the workflow. If that friction persists, adoption will be lumpy and more consultant-led than pure-license-led over the next 1-2 quarters.
Contrarian view: the survey likely overstates immediate urgency because respondents are self-reporting from the security side, while the actual budget owner is usually the app engineering org that resists added release friction. The more investable signal is whether the next 2-3 earnings cycles show rising attach rates for runtime inspection, supply-chain controls, or AI governance modules. If public cyber vendors keep framing AI governance as a board-level narrative without accelerating product revenue, the trade is probably in the "watch" bucket, not a buy-the-theme setup.
For falsification, watch whether mobile/app security spend shows up in Q3-Q4 pipeline commentary, whether appsec renewal rates improve, and whether enterprises start buying integrated controls rather than niche mobile-only tooling. If budget growth stays concentrated in cloud and endpoint while appsec remains flat, this survey will have been more educational than monetizable.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Request DemoOverall Sentiment
mildly negative
Sentiment Score
-0.25