We’re not here to say building your site with AI was a mistake.
AI made it possible for more people to launch websites without hiring a developer, and for many, that decision brought their goals within reach.
However, the speed and convenience come with risks that are both easy to overlook, and not being talked about enough.
What research has found

Veracode ran more than 100 large language models through security-sensitive coding tasks and published the results in July 2025. 45% of the generated code samples introduced a vulnerability from the OWASP Top 10. Cross-site scripting defences failed in 86% of the relevant samples.
The detail that should give everyone pause is that newer and larger models did not perform better. Functional correctness improved across model generations. Security did not, and this isn’t a problem that is quietly solving itself in the background.
Lab results are one thing. Deployed applications are another, and someone checked those, too. A scan of 1,400 applications created with AI apps and site building platforms turned up 2,038 highly critical vulnerabilities, more than 400 leaked secrets, and 175 instances of exposed personal data. Those are real sites, built with the tools in this article, running in production right now.
Finally, the finding that reframes all of it: roughly 80% of developers believe AI tools write more secure code than humans do. The measured evidence says the opposite. If the people writing software for a living are getting this wrong, those building a site from a prompt can’t be expected to know any better.
This is not a downtime story
When one of these defects gets exploited, your site does not go down.
It keeps loading and returning a completely healthy response. Someone injects a script, or redirects part of your traffic, or drains an API key you didn’t know was exposed, or replaces your content with theirs. From the outside, every automated check reports that your website is fine, because by the only measure most people have set up, it is.
That is not an accident. Whoever is doing it would strongly prefer you didn’t notice. A site that goes down gets fixed within hours. A site that keeps serving a healthy 200 response while doing something it shouldn’t can run that way for months.
The same is true of the more mundane failures. A page regenerates and ships empty. A dependency resolves to a package that no longer does what it did. A form submits into nothing. All of them return 200 OK. All of them look, to a basic uptime check, completely healthy.
Our own data: almost nobody is watching for this
We run monitoring for 2.5 million accounts, so we can say something specific about who is actually set up to catch this.
The check that catches a page which loads but is wrong is a keyword check. You give it a word or phrase that only appears when your page is genuinely working, and it alerts you the moment that text disappears. If your content gets replaced, blanked, or broken, the keyword goes with it.
That gap isn’t about money. Keyword monitoring is included on our free plan, alongside 50 monitors and 5-minute checks. It is a gap in awareness, not in access.
The picture barely improves further up. Among paying customers, with every feature unlocked and budget clearly not the constraint, keyword adoption reaches 21.4%. Only 25.9% run more than one type of check on the same site.
So roughly four in five monitored websites are covered by exactly one question: did the server respond? Which means the entire category of failure described above, the one the research says AI-built sites are measurably more prone to, is invisible to almost everybody.
What to actually do about it
You don’t have to rip your site down in a panic or hire a pricey developer. Here are three simple steps to take, in order of highest return.
Put a check on the site. If nothing is watching, start there. One uptime check on the page that matters most, with alerts going somewhere you actually look. Our mobile app, including critical alerts mode iOS, plus integrations like Slack, Microsoft Teams, webhooks, and SMS, mean the difference in discovering the problem in minutes instead of on Monday.
Add one keyword check. Pick a word that only appears when the page is genuinely working. This could be the product name in a shop, your headline on a landing page, or the confirmation text on a booking form. If the page ever loads empty, breaks, or gets replaced with someone else’s content, that word disappears and you get told. Two minutes, free, and it moves you from the 94% into the 5%.
Switch on certificate and domain expiry warnings. These are toggles on the check you already made, not separate work. SSL and domain expiry are among the most common ways a site becomes unreachable while nothing is technically broken, and they are entirely preventable with a few weeks of warning.
That’s the whole list. It takes about five minutes and costs nothing.
The honest summary
There is no credible research showing AI-built sites go offline more often, and you should be sceptical of anyone claiming there is. What the research shows is that AI-generated code carries measurably more defects, that the problem is not improving as models get better, and that the people building with these tools are the least likely to suspect it.
Combine that with our own data, where 19 out of 20 free accounts have no check capable of noticing a page that loads but is wrong, and you get the actual risk. Not that your site will crash. That something will go quietly wrong and keep reporting that everything is fine.
AI-generated code isn’t going away, and it doesn’t have to. The research is clear, though. Vulnerabilities are common, and most websites aren’t monitoring the kinds of failures they can cause. A few extra checks can close that gap in minutes.
Add a keyword check free. Add a free keyword check today. Already have an account? Turn it on in a few clicks. New to UptimeRobot? Start with our Free plan: 50 monitors, 5-minute checks, no credit card required.
UptimeRobot figures from our own base, July 2026 snapshot: 2.5 million accounts, 8.6 million monitors, 4.6 million domains. Check-type adoption measured as the share of accounts running at least one monitor of that type. Keyword monitoring is included on the free plan, so free and paid adoption reflect behaviour rather than entitlement.
Sources: Veracode 2025 GenAI Code Security Report · Cloud Security Alliance research note on AI-generated code vulnerabilities, 2026
