SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Checkmarx launches Fusion hybrid scanning tool for AI code

Checkmarx launches Fusion hybrid scanning tool for AI code

Wed, 29th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Checkmarx has launched Checkmarx Fusion, a hybrid scanning product now available in early access to Checkmarx customers.

The product combines Checkmarx application security engines and security context with Anthropic's Claude model.

Changing code

Checkmarx designed the system to address rising software security risks tied to AI-generated code and increasingly complex development environments. Fusion brings together deterministic scanning methods and AI-based reasoning in a single architecture.

The launch responds to changing software development patterns. In its 2026 Future of Application Security report, Checkmarx said 49% of production code is now AI-generated.

That shift has increased the volume of code security teams must review while expanding the range of languages, frameworks and attack paths they must monitor. According to Checkmarx, many existing tools struggle to keep pace when codebases span both established and newer programming languages.

Hybrid approach

Fusion is part of the Checkmarx One platform. It combines outputs from multiple scanning engines to confirm true positives and reduce false positives, with the aim of improving vulnerability detection accuracy.

Checkmarx also cited benchmark performance for the product, saying Fusion achieved an F1 score of 0.741, which it described as nearly four times the category average.

The architecture uses a deterministic base shaped by Checkmarx's application security research, alongside a multi-model AI engine intended to identify issues beyond fixed rule sets. This includes AI-generated code, emerging languages and mixed-language codebases.

Customers can choose from Claude models for more demanding analysis tasks. The AI layer works within Checkmarx's existing security context so analysis is based on application risk rather than pattern matching alone.

The system is built to let customers manage cost and scan speed by selecting models suited to different workloads. Scanning workloads run within customers' own cloud environments through Amazon Bedrock, so source code does not leave their infrastructure boundary.

That may matter in regulated sectors, where data residency and compliance requirements have slowed adoption of AI-based security tools. Checkmarx said the design is intended to address those concerns while allowing organisations to use AI-assisted scanning at scale.

Industry views

"We are at an inflection point in application security," said Sandeep Johri, Chief Executive Officer, Checkmarx.

"AI has driven code volume, delivery speed, and risk complexity beyond what any organization can manage with yesterday's thinking. Checkmarx Fusion is the answer to that moment: deterministic precision and frontier AI reasoning, delivered in an integrated enterprise-grade cloud architecture. This is how code security has to work from here," added Johri.

Anthropic also commented on the launch. Claude is the large language model referenced in the product design.

"Enterprise application security is one of the most consequential domains for AI reasoning, because the complexity is high, the cost of error is real, and speed matters," said Ashraf Alhashim, Head of Enterprise Security GTM, Anthropic.

"Checkmarx Fusion is a compelling example of what becomes possible when organizations bring frontier AI intelligence to bear within the kind of deep security context Checkmarx has spent decades building," added Alhashim.

Users and security leaders also pointed to growing pressure on application security teams as coding volumes rise. They said the issue is no longer only the presence of vulnerabilities, but whether teams can identify and fix the most serious ones quickly enough.

Security pressure

"With AI generating unprecedented amounts of code, security has to be an enabler, not a bottleneck," said Erik Brown, Business Information Security Officer and AppSec Leader, Nelnet.

"This hybrid approach combining rules-based precision with AI-powered reasoning gives AppSec teams a way to scale while delivering high-fidelity performance. The industry finally has an approach built for what AI demands," added Brown.

"AI-driven security has become a board-level conversation. The question I hear every day is no longer whether we have vulnerabilities-it's whether we've discovered the ones that matter most and whether we're fixing them fast enough," said Mustapha Kebbeh, Chief Security Officer, UKG.

"That's exactly what Checkmarx Fusion is built to address: giving organizations confidence that they're not missing what matters, while enabling teams to prioritize and remediate critical vulnerabilities faster," added Kebbeh.