Open Source AI Statistics 2026: Adoption, Agents, MCP and Security
In 2026, about 92% of US developers use AI coding tools daily while only 29% trust the output; roughly 42% of all code is AI-generated or assisted; the largest MCP registry lists over 72,000 servers. Below: sourced industry figures plus original data from 491 hand-analysed open-source projects.
Adoption and market
- ~92% of US developers use AI coding tools daily; only ~29% trust the generated code.
- ~42% of all code shipped is now AI-generated or AI-assisted (Sonar developer survey).
- The vibe-coding / AI-assisted building market is estimated at $4.7B, growing ~38% year over year.
- ~63% of people building with AI are not professional developers; Deloitte projects over 100 million citizen developers by 2028.
- ~77% of professional developers still refuse to ship unreviewed AI code to production.
Agents, MCP and the tooling ecosystem
- Enterprise questions about multi-agent systems grew over 1,400% between early 2024 and mid 2025 (Gartner); companies deploying agents run about 12 on average.
- The largest MCP registry lists 72,000+ servers; over 60,000 open-source projects reference the Model Context Protocol.
- GitHub Spec Kit, the leading open-source spec-driven development CLI, passed 93,000 stars and supports 30+ coding agents.
- Community marketplaces for Claude Code list roughly 3,000+ skills and 470+ plugins as of mid-2026.
- Open-weight models closed most of the coding gap: 2026 releases run agentic workloads on a single consumer GPU.
Security of AI-generated code
- ~44% of AI code-generation tasks introduce a security vulnerability (Veracode GenAI Code Security Report 2026).
- Average security pass rate across major models: 56% — essentially unchanged year over year.
- 1 in 4 generated samples contains a confirmed vulnerability (AppSec Santa: 534 samples, 6 LLMs).
- AI-generated code is implicated in roughly 1 in 5 enterprise breaches (Aikido Security).
- ~60% of developers never adjust permission scopes in generated code; AI-written infrastructure code raises identity-related vulnerabilities by ~28%.
- ~73% of audited AI systems show exposure to prompt injection.
Original data: inside a hand-analysed catalog of 491 projects
The figures below are RepoLoot's own, derived from analysing 491 curated open-source projects for difficulty, commercial potential and technology focus. They describe the buildable layer of open source — projects selected because something real can be built on them. Cite them with a link to this page; the dataset is refreshed as the catalog grows.
| Metric | Value | Share of catalog |
|---|---|---|
| Projects rated easy to start with (Beginner difficulty) | 416 of 491 | 85% |
| Projects with commercial potential 4/5 or higher | 246 of 491 | 50% |
| Projects with the top 5/5 potential rating | 85 of 491 | 17% |
| Easy to deploy AND high potential (the sweet spot) | 215 of 491 | 44% |
| Distinct technology tags across the catalog | 1,196 | — |
| Agent frameworks and orchestration projects | 87 | 18% |
| Coding agents and assistant tooling | 46 | 9% |
| CLI and terminal (TUI) tools | 36 | 7% |
| AI code security, review and scanning projects | 27 | 5% |
| Local and self-hosted AI projects | 23 | 5% |
What the numbers say together
Three storylines run through every table on this page. Adoption is no longer the story — with 92% daily use, AI-assisted development is simply how software gets written. Trust is the story: a 56% security pass rate and a 29% trust figure explain why spec-driven workflows and review tooling are the fastest-growing categories. And the opportunity moved up a layer: with 100 million citizen developers coming, the scarce resource is not code generation but knowing what is worth building — which is precisely the question a curated catalog answers.
Frequently asked questions
- How many developers use AI coding tools in 2026?
- Roughly 92% of US developers report daily use of AI coding tools, but only about 29% say they trust the generated code — the defining gap of 2026. About 42% of all shipped code is now AI-generated or AI-assisted.
- How many MCP servers exist in 2026?
- The largest public registry lists over 72,000 MCP servers, and more than 60,000 open-source projects reference the Model Context Protocol. Despite that volume, most internal systems and vertical SaaS products still have no server at all.
- How much AI-generated code contains security vulnerabilities?
- About 44% of AI code-generation tasks introduce a risky vulnerability (Veracode 2026), one in four generated samples contains a confirmed flaw (AppSec Santa), and AI-written code is implicated in roughly one in five enterprise breaches (Aikido Security).
- Can I cite these statistics?
- Yes — cite this page with a link to repoloot.com. Industry figures carry their original sources above and should be credited to those studies; the catalog dataset (491 analysed projects, difficulty and potential distributions) is RepoLoot original data and is refreshed as the catalog grows.