On May 19, 2026, a press release hit GlobeNewswire claiming that 81% of enterprise tech leaders report production failures from AI-generated code. Within hours, the stat was everywhere. Nobody checked who made the number, how they made it, or why. We checked. What we found is a pipeline designed to produce headlines, not research.
The AI industry has a manufactured consensus problem. Vendor-funded surveys are designed to produce alarming or impressive statistics. Those statistics are laundered through press release distribution wires into mainstream tech coverage, where they are cited as independent research. Analysts pick them up. Investors repeat them. Product managers put them in slide decks. Within 48 hours, a number that was engineered to sell a specific product becomes a fact that everybody knows.
Nobody covers the machinery that produces these numbers. That machinery is not hidden. It is sitting on the websites of the companies that built it, described in plain language, if anyone bothers to look.
We looked.
The Pipeline
Before we get to specific cases, here is how the pipeline works. It is the same every time, with minor variations. Once you see the structure, you will recognize it in every "new research shows" headline you read.
Step 1: A vendor identifies a market fear that sells their product. If you sell CI/CD tooling, the fear is "AI-generated code is breaking production." If you sell data security, the fear is "AI agents are causing breaches." The fear must be real enough to feel plausible and specific enough to have a product-shaped solution.
Step 2: The vendor commissions a "research firm." Sometimes this is a legitimate survey company. Sometimes it is a content marketing agency or a lead generation shop with "research" somewhere in its service list. The distinction matters. Legitimate survey firms have methodological standards. Content marketing agencies have clients.
Step 3: The research firm designs survey questions to produce headline-friendly numbers. This is the crucial step. The questions are not designed to discover what is happening. They are designed to produce a number that will look good in a press release. We will see exactly how this works in a moment.
Step 4: The survey goes to a small, often self-selected sample. Two hundred respondents is typical. Sometimes fewer. The margin of error is large enough to drive a truck through, but margins of error do not appear in press release headlines.
Step 5: The results are packaged as a press release and distributed through GlobeNewswire, PRNewswire, or BusinessWire. These services do not fact-check. They distribute. That is their business model. But the releases carry the visual authority of news, and news aggregators index them alongside actual journalism.
Step 6: Tech press picks it up as "new research shows..." and analysts cite it. Within days it appears in investor decks, board presentations, and conference keynotes. The vendor is mentioned as the sponsor. The methodology is not discussed. The number is the story.
Step 7: Nobody checks the methodology, because the number confirms existing anxieties. AI code is scary. Breaches are scary. The stat feels right, so it must be right. The correction, if it ever comes, takes months. The original number has a permanent head start.
A vendor survey can go from commissioned to conventional wisdom in 48 hours. The correction, if it ever comes, takes months.
Case Study: CloudBees and the 81% Statistic
On May 19, 2026, CloudBees published a press release on GlobeNewswire with the headline: "81% of Enterprise Technology Leaders Report Production Failures from AI-Generated Code."1 The number is specific. It is alarming. It is exactly the kind of statistic that gets shared without scrutiny.
CloudBees is a CI/CD platform vendor. They sell tools for managing software delivery pipelines. If AI-generated code is causing production failures, CloudBees has products you should buy. That is not a coincidence. That is the business model.
The research was conducted by TrendCandy, described in the press release as an "independent research agency." We went to TrendCandy's website. Their about page describes what they do.2 Their methodology page is more illuminating.3 TrendCandy states, in their own words, that they "start with compelling headlines and reverse-engineer them into survey questions."
Read that again. They start with the headline. Then they write the questions.
This is not research methodology. This is headline manufacturing. A legitimate survey starts with a question and discovers the answer. TrendCandy starts with the answer and constructs the question. They say this openly. It is their selling point. It is how they pitch themselves to clients who need a number that will get media coverage.
The CloudBees survey used 213 respondents with a +/-8% margin of error.1 For context, an 8% margin of error means the real number could be anywhere from 73% to 89%. That range is wide enough to be nearly meaningless, but "somewhere between 73% and 89%" does not make a good headline. 81% makes a good headline.
The term "production failures" is not defined in the press release. Does it mean a full outage? A bug that reached production? A test that failed in staging? A code review comment? The definition matters enormously. If "production failure" means "any bug from AI code reached any non-dev environment," then 81% is probably low. If it means "AI code caused a customer-facing outage," that is a very different and much more alarming claim. The survey does not distinguish. That ambiguity is a feature, not a bug.
The full report is gated behind a lead-generation form on CloudBees' website.4 To read the methodology, you must give CloudBees your name, email, company, and job title. This means the methodology is available only to people who have entered the vendor's sales pipeline. Journalists who want to check the methodology before reporting the number must first become a sales lead. Most do not bother.
Case Study: Kiteworks and the 65% Statistic
Kiteworks is a data security vendor. In their 2026 forecast report, they claimed that 65% of organizations experienced cybersecurity incidents caused by AI agents.5
The CloudBees study at least used an outside firm. Kiteworks did not. This survey was self-commissioned and self-conducted. Kiteworks asked the questions, collected the answers, analyzed the results, and published the conclusions. There was no independent research partner. No third-party validation. No external methodology review.
The sample was 225 respondents. The report contains no methodology appendix. There are no confidence intervals. There is no description of how respondents were selected, how questions were worded, or how "cybersecurity incidents caused by AI agents" was defined. Was it a data breach? An unauthorized access attempt? A policy violation? A false positive from a monitoring tool? The report does not say.
The timing is instructive. The report was released alongside Kiteworks' launch of their "Compliant AI" product, a data governance layer for AI agents.6 The report says AI agents are causing security incidents. The product launch says Kiteworks can fix that. The report creates the demand. The product launch fulfills it. Same week.
Here is the thing about the 65% number. Other surveys in the same period produced dramatically different results. The Cloud Security Alliance found 53% of organizations experienced AI agent scope violations, a study with disclosed methodology and no product launch attached. Proofpoint, surveying over 1,400 security professionals, found roughly half experienced AI incidents, with full methodology published. The numbers vary, but none of the independently conducted surveys with larger samples and disclosed methodology produced anything close to 65%.
The spread across these surveys is not explained by margin of error. It is explained by who asked the questions, how they asked them, and what answer they needed.
They start with the headline. Then they write the questions. They say this openly. It is their selling point.
What Real Research Looks Like
The manufactured numbers are easy to spot once you know what legitimate research looks like. Here is the contrast.
MIT, August 2025: Researchers found that 95% of generative AI pilots were failing to move past the pilot stage.7 This is an alarming number from a credible source. MIT is an academic institution with no product to sell. The research went through peer review. The methodology is public. The sample is described. The definitions are clear. You can disagree with their conclusions, but you can evaluate how they reached them.
Lightrun/VentureBeat, 2026: A survey finding that 43% of AI-generated code changes need debugging in production.8 Lightrun is also a vendor (they sell debugging tools), so they have commercial interest too. The difference is not the lower number. The difference is that the methodology is disclosed, the vendor relationship is stated upfront, and the full results are available without entering a sales funnel. Transparency, not the magnitude of the number, is what separates research from marketing.
METR, 2025: An independent research organization found that developers were 19% slower when using AI coding tools on real-world tasks. This study used controlled experiments, not surveys. The methodology is reproducible. METR has no product to sell. The finding contradicts the narrative that AI tools make developers faster, which is exactly what makes it credible. Nobody funds research that undermines their own product.
Pragmatic Engineer: Gergely Orosz runs an independent newsletter covering the software industry. No vendor funding. No sponsored research. No gated reports. When he cites a statistic, he traces it to its source and evaluates the methodology. This is what journalism is supposed to look like. It is also increasingly rare.
The pattern across legitimate research is consistent: disclosed methodology, adequate sample sizes, no commercial interest in the outcome, and results that are available without entering a sales funnel. The pattern across vendor research is also consistent: undisclosed methodology, small samples, direct commercial interest, and results gated behind lead-gen forms.
The Press Release Wire Problem
GlobeNewswire, PRNewswire, and BusinessWire are not news organizations. They are distribution services. Companies pay them to distribute press releases. The services do not fact-check the claims in those releases. They do not evaluate methodology. They do not require that statistics be independently verified. They distribute what they are paid to distribute.
This is fine, as long as everyone understands what these services are. The problem is that news aggregators index press release wire content alongside actual journalism. Google News surfaces GlobeNewswire releases. News apps include them in tech feeds. The visual presentation is indistinguishable from a news article. A reader scanning headlines has no way to tell the difference between "81% of enterprise tech leaders report production failures" published as a paid press release and "81% of enterprise tech leaders report production failures" reported by an independent journalist who checked the methodology.
The wires are the laundering mechanism. A statistic that originates as a vendor-funded survey becomes, through the wire, something that looks like news. Once it looks like news, it gets cited as news. Once it is cited as news, it becomes a fact. The provenance is lost within a single news cycle.
Why This Matters Now
The AI industry is making decisions based on these numbers. Engineering leaders are setting policy based on them. Investors are allocating capital based on them. Regulators are forming opinions based on them. When the numbers are manufactured, the decisions are wrong. Not slightly wrong. Wrong in a way that benefits the manufacturers.
The inflated numbers create artificial urgency that redirects engineering budgets toward vendor solutions for vendor-defined problems. They make the AI transition harder than it needs to be, because the baseline anxiety is calibrated to manufactured statistics rather than observed reality. A company that reads "81% failure rate" makes different decisions than a company that reads "43% need debugging." The first number produces panic buying. The second produces measured investment. The vendor needs the first number.
The Speed Problem
This is not a new problem. The pharmaceutical industry has funded research that supports its products for decades. The cybersecurity industry has inflated breach statistics since the invention of the firewall. Fintech companies commission surveys about financial anxiety and then sell financial products. The vendor-funded research pipeline is as old as vendor-funded research.
What is new is the speed.
In 2026, a vendor can commission a survey, have it conducted, publish the results via press release wire, and watch the statistic enter mainstream tech coverage in under a week. The CloudBees 81% number went from GlobeNewswire to tech news aggregators to social media in less than 48 hours. It will appear in analyst reports within a month. It will be cited in vendor competitor analysis decks within two months. It will be referenced in regulatory discussions within a quarter.
The correction cycle is vastly slower. If someone publishes a methodological critique, it will reach a fraction of the audience that saw the original number. It will not appear in the same news aggregators. It will not be picked up by the same tech press. It will not enter the same slide decks. The original number has an insurmountable distribution advantage because it was designed for distribution. The critique was designed for accuracy. In the attention economy, distribution wins.
The AI industry is moving faster than any previous technology cycle. The decisions being made today, about regulation, about investment, about adoption, about risk, are being made on a foundation of numbers that were engineered to sell products. Not all of them. But enough of them that the baseline is contaminated.
What Would Fix This
There are simple things that would make this better. None of them are likely to happen, because none of them serve the interests of the people who would need to implement them.
Press release wires could require methodology disclosure. If you claim a statistic in a press release, the methodology should be attached. Not gated behind a lead-gen form. Attached. GlobeNewswire, PRNewswire, and BusinessWire could implement this requirement tomorrow. They will not, because their clients do not want it, and their clients are the ones paying.
Tech journalists could check the source. When a press release says "new research shows," the journalist could visit the research firm's website. They could look at the sample size. They could check whether the methodology is disclosed. They could note that the research was funded by a company that sells products addressing the problem the research describes. Some journalists already do this. Most do not, because the press release is the story, and checking the methodology is work that does not produce clicks.
Readers could demand provenance. When you see a statistic in a tech article, you could ask: Who funded this? How many people were surveyed? Is the methodology public? Does the funder sell a product that addresses the problem described? These questions take thirty seconds. The answers are usually available if you look. Most people do not look, because the statistic confirms something they already believe, and confirmation is more comfortable than verification.
Independent research organizations could fill the gap. METR, academic institutions, and independent journalists like Pragmatic Engineer produce research that is not designed to sell products. They are chronically underfunded compared to the vendor research machine. Supporting independent research is the most direct fix, and it is the one that requires the most effort from the people who would benefit from it.
The Receipts
We are a publication that covers AI with receipts. Here are ours.
TrendCandy's website says they reverse-engineer survey questions from headlines. We did not interpret that. We read it on their website.3 CloudBees' report is gated behind a lead-gen form. We filled out the form to confirm this.4 Kiteworks' survey was self-commissioned and self-conducted with 225 respondents and no methodology appendix. We read the report.5 The Cloud Security Alliance and Proofpoint surveys we cite as counterpoints both have published methodologies and larger samples. We checked.
Every link in the citations section below goes to a primary source. Not a summary. Not a secondhand account. The source. If we got something wrong, the evidence to prove it is right there.
The AI industry's most consequential numbers are being manufactured by companies that profit from the fear those numbers create. The pipeline is not hidden. The methodology is not secret. It is sitting on TrendCandy's website, described in their own marketing copy, available to anyone who does what journalists are supposed to do: check the source.
We checked. Now you can too.
Disclosure
This article was written with the assistance of Claude, an AI made by Anthropic. Anthropic is a major player in the AI industry discussed in this piece. That conflict is real and you should weigh it accordingly. We have no financial relationship with any vendor mentioned in this article, and no vendor was given pre-publication review. Every claim is sourced. Every source is linked. Corrections welcome at [email protected].
Sources
- GlobeNewswire, "81% of Enterprise Technology Leaders Report Production Failures from AI-Generated Code, New Research Shows." CloudBees press release, May 19, 2026. Link.
- TrendCandy, About page. Describes their approach as an "independent research agency." Link.
- TrendCandy, homepage. States methodology of starting with compelling headlines and reverse-engineering survey questions. Link.
- CloudBees, "2026 State of Code Abundance Report." Full report gated behind lead-generation form. Link.
- Kiteworks, "2026 Data Security, Compliance & Risk Forecast Report." Self-commissioned, self-conducted survey. 225 respondents, no methodology appendix. Link.
- Kiteworks, "Kiteworks Launches Compliant AI Data Layer for Governance of AI Agents." Press release timed to forecast report. Link.
- Fortune, "A new MIT report says 95% of generative AI pilots at companies are failing." August 18, 2025. Link.
- VentureBeat, "43% of AI-generated code changes need debugging in production, survey finds." Lightrun-sponsored survey with disclosed methodology. Link.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.