Collaboration
Source Code Security in the AI Era
Why RayAegis combines traditional tools with frontier AI

At RayAegis, we have been researching a frontier AI method for source code security and comparing its findings with those from traditional tools. Our practical observation is that established analysis provides a stable and verifiable baseline, while AI-assisted review can raise questions about application logic and uncover issues we had not previously seen. For systems with serious consequences if they fail, we recommend using both approaches and verifying material findings with security experts.
The value of traditional tools
In our work, the most valuable qualities of the established analysis were stability, reliability, repeatability and consistency. Its findings could be revisited and checked against the source code. A repeatable baseline helps teams compare releases, track remediation and explain why an issue was reported. These qualities matter to organizations that need decisions supported by evidence rather than a single unrepeatable result.
Traditional analysis also provides systematic coverage of many technical weakness patterns and code paths. Its limits became more apparent in our comparison when a security question depended on the intended meaning of a workflow or a business rule. A sequence of individually valid actions can still produce an outcome that the application should not permit.
Where frontier AI added value
Our AI-assisted method helped us examine relationships among code paths, authorization assumptions, application state and expected behavior. It surfaced several issues that had not appeared in our earlier reviews, particularly where understanding context mattered. We treated those outputs as hypotheses to investigate, rather than as automatically confirmed vulnerabilities.
Frontier AI also has limits. Its answer can change with the model, the context supplied and the questions asked. A persuasive explanation may describe a path that cannot occur in the real application. The value comes from using AI to direct expert attention to a testable scenario, then verifying that scenario in the code and, where appropriate, in a controlled test.
A review process for critical systems
We recommend starting from an approved source snapshot. Run traditional tools with recorded versions, rules and settings to establish a repeatable baseline. Conduct a separate frontier AI review with the architecture and business context needed to understand intended behavior, under the organization’s source code handling requirements. Reconcile the two sets of leads, then have security engineers trace the relevant code, reproduce important scenarios, remove duplicates and assess impact. After remediation, retest the affected paths.
This approach is especially useful for banks, government systems and other critical services. Traditional tools contribute disciplined, auditable analysis; frontier AI can explore questions that a fixed review may not have asked. Human reviewers remain responsible for confirming the evidence and making the final risk decision.
The scope of our conclusion
These are qualitative observations from our hands-on research. Our conclusion is narrower and actionable: in our work, the two approaches contributed different evidence, and using them together strengthened the review.