Open Source AI Statistics 2026: Adoption, Agents, MCP and Security

7 minUpdated:

In 2026, about 92% of US developers use AI coding tools daily while only 29% trust the output; roughly 42% of all code is AI-generated or assisted; the largest MCP registry lists over 72,000 servers. Below: sourced industry figures plus original data from 491 hand-analysed open-source projects.

Adoption and market

  • ~92% of US developers use AI coding tools daily; only ~29% trust the generated code.
  • ~42% of all code shipped is now AI-generated or AI-assisted (Sonar developer survey).
  • The vibe-coding / AI-assisted building market is estimated at $4.7B, growing ~38% year over year.
  • ~63% of people building with AI are not professional developers; Deloitte projects over 100 million citizen developers by 2028.
  • ~77% of professional developers still refuse to ship unreviewed AI code to production.

Agents, MCP and the tooling ecosystem

  • Enterprise questions about multi-agent systems grew over 1,400% between early 2024 and mid 2025 (Gartner); companies deploying agents run about 12 on average.
  • The largest MCP registry lists 72,000+ servers; over 60,000 open-source projects reference the Model Context Protocol.
  • GitHub Spec Kit, the leading open-source spec-driven development CLI, passed 93,000 stars and supports 30+ coding agents.
  • Community marketplaces for Claude Code list roughly 3,000+ skills and 470+ plugins as of mid-2026.
  • Open-weight models closed most of the coding gap: 2026 releases run agentic workloads on a single consumer GPU.

Security of AI-generated code

  • ~44% of AI code-generation tasks introduce a security vulnerability (Veracode GenAI Code Security Report 2026).
  • Average security pass rate across major models: 56% — essentially unchanged year over year.
  • 1 in 4 generated samples contains a confirmed vulnerability (AppSec Santa: 534 samples, 6 LLMs).
  • AI-generated code is implicated in roughly 1 in 5 enterprise breaches (Aikido Security).
  • ~60% of developers never adjust permission scopes in generated code; AI-written infrastructure code raises identity-related vulnerabilities by ~28%.
  • ~73% of audited AI systems show exposure to prompt injection.

Original data: inside a hand-analysed catalog of 491 projects

The figures below are RepoLoot's own, derived from analysing 491 curated open-source projects for difficulty, commercial potential and technology focus. They describe the buildable layer of open source — projects selected because something real can be built on them. Cite them with a link to this page; the dataset is refreshed as the catalog grows.

MetricValueShare of catalog
Projects rated easy to start with (Beginner difficulty)416 of 49185%
Projects with commercial potential 4/5 or higher246 of 49150%
Projects with the top 5/5 potential rating85 of 49117%
Easy to deploy AND high potential (the sweet spot)215 of 49144%
Distinct technology tags across the catalog1,196
Agent frameworks and orchestration projects8718%
Coding agents and assistant tooling469%
CLI and terminal (TUI) tools367%
AI code security, review and scanning projects275%
Local and self-hosted AI projects235%

What the numbers say together

Three storylines run through every table on this page. Adoption is no longer the story — with 92% daily use, AI-assisted development is simply how software gets written. Trust is the story: a 56% security pass rate and a 29% trust figure explain why spec-driven workflows and review tooling are the fastest-growing categories. And the opportunity moved up a layer: with 100 million citizen developers coming, the scarce resource is not code generation but knowing what is worth building — which is precisely the question a curated catalog answers.

Frequently asked questions

How many developers use AI coding tools in 2026?
Roughly 92% of US developers report daily use of AI coding tools, but only about 29% say they trust the generated code — the defining gap of 2026. About 42% of all shipped code is now AI-generated or AI-assisted.
How many MCP servers exist in 2026?
The largest public registry lists over 72,000 MCP servers, and more than 60,000 open-source projects reference the Model Context Protocol. Despite that volume, most internal systems and vertical SaaS products still have no server at all.
How much AI-generated code contains security vulnerabilities?
About 44% of AI code-generation tasks introduce a risky vulnerability (Veracode 2026), one in four generated samples contains a confirmed flaw (AppSec Santa), and AI-written code is implicated in roughly one in five enterprise breaches (Aikido Security).
Can I cite these statistics?
Yes — cite this page with a link to repoloot.com. Industry figures carry their original sources above and should be credited to those studies; the catalog dataset (491 analysed projects, difficulty and potential distributions) is RepoLoot original data and is refreshed as the catalog grows.

Related guides