How safe are apps built with AI?
AI app builders ship a working app fast. We looked at the public response headers of 436 live apps makers listed themselves, to see which baseline browser protections are in place. We read only what any visitor’s browser receives.
Which protections are present
Share of apps that send each standard browser protection.
| Content Security Policy | 6.4% | |
| HTTPS enforced (HSTS) | 89% | |
| Clickjacking protection | 9.4% | |
| No MIME sniffing | 81.7% | |
| Referrer policy | 80% | |
| Permissions policy | 6.2% | |
| Cross-origin isolation | 2.3% |
How many protections at once
Share of apps by the number of the seven protections they send.
| 0 of 7 | 6.2% | |
| 1 of 7 | 12.2% | |
| 2 of 7 | 3.2% | |
| 3 of 7 | 70% | |
| 4 of 7 | 1.1% | |
| 5 of 7 | 3.2% | |
| 6 of 7 | 3% | |
| 7 of 7 | 1.1% |
These are the defaults a reviewer sets before an app meets real users, and they are exactly the defaults an AI builder leaves out. Missing headers are not the whole picture, but they are a reliable sign that no one has done the security pass. That pass, done once, is what turns a prototype into something you can put your name on. Read the guide on launching an AI-built app safely.
Method. Public response headers only, fetched once per app from its own public showcase listing. We recorded whether each standard browser protection is present and whether a JavaScript source map is served publicly. We never logged in, called an API, submitted a form, or inspected page or script contents for secrets. No app is named. Aggregates only; no store or app is named. Related research: all studies.