Every few weeks another coding tool ships a capability that makes writing code faster. The defect rate in what they write has not moved with it.

Short answer: AI coding tools expanded steadily through 2026, while Veracode found AI-generated code carrying 2.74 times more vulnerabilities than human-written code and Georgia Tech tracked CVEs traced to AI code rising from 6 to 35 in three months. Output grew; the defect rate did not fall.

Key takeaways

  • Through 2026 the major AI coding tools continued expanding, with interoperability between assistants and agentic workflow features becoming standard rather than novel. Over the same period,.
  • 124 live listings in this category publish a rate, at a median top-of-range of $100 an hour and a ceiling of $300.
  • The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
  • Applications screen on a short skills assessment rather than a resume or interview.

What was reported

The finding

Through 2026 the major AI coding tools continued expanding, with interoperability between assistants and agentic workflow features becoming standard rather than novel. Over the same period, Veracode's GenAI Code Security Report tested more than 100 large language models across Java, JavaScript, Python and C# and found AI-generated code contained 2.74 times more vulnerabilities than human-written code, with 45% of samples introducing OWASP Top 10 vulnerabilities and Java failing security checks 72% of the time. The report noted this performance remained largely unchanged even as models improved at producing syntactically correct code. Georgia Tech's Vibe Security Radar recorded CVEs directly traced to AI-generated code rising from 6 in January 2026 to 15 in February and 35 in March, with researchers estimating the true count five to ten times higher.

Veracode tested more than 100 models across four languages and found AI-generated code carrying 2.74 times the vulnerabilities of human-written code, 45% of samples introducing an OWASP Top 10 issue, and Java failing security checks 72% of the time. The finding that matters most: this was largely unchanged as models improved at producing code that compiles.

What the listings pay

Georgia Tech's tracker puts numbers on the consequence, tracing CVEs directly to AI-generated code and recording 6 in January, 15 in February and 35 in March 2026, with the true figure estimated five to ten times higher across open source.

#RoleAdvertised ratePlatform
1CUDA Engineering Expert$300 to $300 an hourMercor
2Cybersecurity Research Expert, Offensive Security & Vulnerability Research$200 to $250 an hourMercor
3Machine Learning Engineer Talent Network$70 to $250 an hourMercor
4Legacy Codebase Migration Expert$200 to $200 an hourMercor
5UK-Based Data Engineering Experts$140 to $200 an hourMercor
6AI Software Engineering Domain Expert$100 to $200 an hourmicro1
7AI/ML Engineer$70 to $200 an hourmicro1
8Engineering / Platform Professionals$80 to $160 an hourMercor
9Open Source Applied Engineer Talent Network$100 to $150 an hourMercor
10Backend Engineer Talent Network$70 to $150 an hourMercor

Source: 124 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

Coding Tools Keep Shipping. The Review Burden Is What Grows

How this compares across the board

A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.

CategoryListingsMedian lowMedian topHighest
Legal95$100$140$400
Medical68$77$120$400
Consulting45$80$120$280
Finance94$80$110$280
Engineering114$70$100$300
Research/PhD132$70$90$280
Writing36$40$80$280
Bilingual78$44$52$120
Annotation25$12$24$120

Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.

What it means for you

More code, same defect rate, means more defects. That is why review is the part of engineering that grows. Across 124 live engineering and code listings on our board that publish a rate, the median top-of-range is $100 an hour, reaching $300.

Why capability gains have not closed the security gap

Models improved fastest at the thing that is easiest to measure and reward: producing code that runs. Security is a property of what the code does under conditions the training signal rarely contains.

That is why Veracode found newer and larger models producing no more secure code than their predecessors. It is not a scale problem that another generation solves, which is what makes the review demand durable rather than transitional.

The market has priced this. Nearly 70% of US software development postings on Indeed in Q1 2026 were senior-level, with Indeed attributing the skew to companies needing people to direct AI tools and review the code they produce.

The specific skill being paid for

Reading unfamiliar code that compiles, looks correct, and is quietly unsafe. That is a different muscle from writing code, and most engineers have exercised it far less.

Most listings do not require a security background. They want strong engineers who read carefully and can explain precisely why something is wrong, which is what makes the output useful to the lab.

For engineers between roles this has a practical edge over waiting: it screens on a sample task rather than a resume, and it produces recent describable work in exactly the area employers say they are hiring for.

Who should apply

Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.

Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.

Frequently asked questions

Are AI coding tools getting more secure?

Veracode found security performance largely unchanged even as models improved at producing syntactically correct code, with newer and larger models not generating significantly more secure code.

How much less secure is AI-generated code?

2.74 times more vulnerabilities than human-written code, with 45% of samples introducing an OWASP Top 10 vulnerability and Java failing security checks 72% of the time.

Is the problem measurable in the wild?

Georgia Tech's tracker recorded CVEs traced directly to AI-generated code rising from 6 in January 2026 to 15 in February and 35 in March, estimating the true count five to ten times higher.

Does this create work or remove it?

More code at the same defect rate means more defects. Nearly 70% of US software development postings in Q1 2026 were senior-level, attributed to needing people to direct and review AI output.

What does code evaluation work pay?

Across 124 live engineering and code listings publishing a rate, the median top-of-range is $100 an hour, reaching $300.

Do I need a security background?

Usually not. Most listings want strong engineers who read unfamiliar code carefully and can explain precisely why it is wrong.

How do these roles screen?

Most use a short sample task rather than a resume screen, which is a meaningful difference for engineers between roles.

Sources

  1. Veracode, AI-generated code: a double-edged sword for developers
  2. Georgia Tech Research, Bad vibes: AI-generated code is vulnerable, researchers warn
  3. Cloud Security Alliance, Vibe coding's security debt: the AI-generated CVE surge

See every live role

The full board updates several times a week, with the advertised rate on each listing and closed roles removed.

Browse all AI jobs