/research · October 1, 2026

How safe are apps built with AI?

AI app builders ship a working app fast. We looked at the public response headers of 436 live apps makers listed themselves, to see which baseline browser protections are in place. We read only what any visitor’s browser receives.

93.6%ship with no Content Security Policy
90.6%have no clickjacking protection
3/7median number of standard protections in place

Which protections are present

Share of apps that send each standard browser protection.

Content Security Policy6.4%
HTTPS enforced (HSTS)89%
Clickjacking protection9.4%
No MIME sniffing81.7%
Referrer policy80%
Permissions policy6.2%
Cross-origin isolation2.3%

How many protections at once

Share of apps by the number of the seven protections they send.

0 of 76.2%
1 of 712.2%
2 of 73.2%
3 of 770%
4 of 71.1%
5 of 73.2%
6 of 73%
7 of 71.1%

These are the defaults a reviewer sets before an app meets real users, and they are exactly the defaults an AI builder leaves out. Missing headers are not the whole picture, but they are a reliable sign that no one has done the security pass. That pass, done once, is what turns a prototype into something you can put your name on. Read the guide on launching an AI-built app safely.

Check your app ›

Method. Public response headers only, fetched once per app from its own public showcase listing. We recorded whether each standard browser protection is present and whether a JavaScript source map is served publicly. We never logged in, called an API, submitted a form, or inspected page or script contents for secrets. No app is named. Aggregates only; no store or app is named. Related research: all studies.