
Findings and evidence
Mandiant describes an internal approach to AI-assisted source review that combines structured analysis, validation and human expertise. It reports findings from customer engagements and explains how review outputs are checked before being treated as real issues.
Why it matters
The useful evaluation unit is a confirmed, relevant finding with reproducible evidence and a reviewed fix. Track false positives, scope and analyst effort rather than judging a review by the number of generated reports.
Scope and limits
The reported results come from the publisher’s engagements, not a randomized comparison across products. Performance may differ with codebase, model version and validation practices.
Primary source
Google / Mandiant: original publication. Source published 2026-08-18. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.