The Embedded Software Industry in 2025: Navigating AI Adoption and Supply Chain Transparency

By Corey Hamilton, Senior Solutions Manager, Black Duck [ Join Cybersecurity Insiders ]
Create a widescreen image that dynamically illustrates multiple encrypted data streams in motion,

The embedded software landscape is undergoing a significant transformation, driven by the rapid adoption of artificial intelligence (AI) and the increasing importance of software supply chain management. A recent comprehensive survey of 785 professionals in the embedded software industry reveals key trends and challenges that are reshaping the way companies develop, deploy, and secure their software.

The AI Revolution: Opportunities and Risks

AI has become an integral part of embedded software development, with 89.3% of companies already utilizing AI-powered coding assistants. Moreover, 96.1% of respondents reported using open-source AI models in their products, highlighting the pervasive nature of AI in modern embedded systems. However, this rapid adoption has outpaced the development of necessary governance and risk management practices.

The survey highlights a significant governance gap, with 21.1% of organizations lacking confidence in their ability to prevent AI-generated code from introducing critical defects, security vulnerabilities, or legal risks related to open source license obligations. This gap is particularly concerning given that 72% of companies that have prohibited the use of AI coding assistants acknowledge that their developers are using them against company policy. This increases the likelihood of AI-generated code introducing critical defects and vulnerabilities that won’t be caught without proper testing, creating unmanaged risks to software quality, security, and intellectual property.

The Rise of Software Bills of Materials (SBOMs)

The software supply chain is another critical area of focus, with SBOMs emerging as a commercial imperative. Over 70% of organizations now produce SBOMs, driven primarily by customer and partner requirements. This represents a shift in responsibilities as these requirements have previously been driven mostly by industry regulations. This shift underscores the market’s demand for improved transparency and accountability in software development.

The adoption of SBOMs is not merely a compliance exercise; it has become a competitive differentiator. Companies that can demonstrate transparency and control over their software supply chains are better positioned to win and retain customers. The survey indicates that 80.4% of companies are confident in their ability to produce complete and accurate SBOMs, suggesting a maturing of the necessary tools and processes.

However, as consumers and partner organizations increasingly take the lead in defining SBOM requirements, software producers should expect those requirements to evolve more quickly and with greater variability than in the past. They should be prepared to expand the scope of visibility provided by their SBOMs as technologies evolve and should be able to share these insights with consumers in a variety of formats.

Evolving Skillsets and Compliance Challenges

The role of the embedded developer is also evolving, with a growing emphasis on memory-safe languages. The survey reveals that 80.4% of companies have adopted memory-safe languages, reflecting a shift towards more secure coding practices.

Compliance in the embedded software industry remains fragmented, with no single standard dominating. Internal coding standards are the most common source of authority, cited by 22.2% of respondents, followed closely by established frameworks like MISRA C/C++ and ISO 26262. This fragmentation necessitates flexible and configurable software testing tools that can map defects and vulnerabilities to custom standards and frameworks so that stakeholders can track compliance and prioritize issues for remediation.

Bridging the Perception Gap

A significant perception gap exists between management and engineers regarding the quality of software they’re releasing. While 85% of VPs and directors believe their projects are successful, only 64% of hands-on developers share this optimism.

As leaders focus on meeting release timelines and high-level metrics, their development teams are concerned about the compromises they were forced to make in order to ship their software on time. This disconnect highlights the need for better communication and a shared understanding of the impact that workarounds and unresolved defects have on software quality, security, and risks to the organization.

Recommendations for Industry Stakeholders

To navigate these challenges, industry stakeholders must adopt a holistic approach that integrates technology, people, and governance. Employees should be empowered to embrace the significant business advantages that AI enables but must be able to do so in a safe and responsible manner.

Managers should establish the guardrails and processes that promote safe AI usage, including formal AI governance policies and the ability to properly track usage and enforce those policies. AI coding assistants should be viewed as valuable but potentially unreliable resources, requiring oversight and comprehensive quality and security testing.

Development leaders need to continue investing in training and tooling for emerging skills like secure AI usage and memory-safe languages and must also improve visibility into software quality to ensure executives understand the risks created when compromises are made to meet release deadlines.

Additionally, security and compliance professionals should update their threat models to account for emerging AI-specific risks and leverage their SBOMs as strategic assets to improve incident response and streamline risk management. By doing so, companies can transform systemic risks into competitive advantages, driving innovation while ensuring reliability, security and compliance.

Conclusion

The embedded software industry is at a critical juncture, with AI adoption and supply chain transparency redefining the landscape. By understanding these trends and addressing the associated challenges, companies can position themselves for success in a rapidly evolving market. The key findings from the “State of Embedded Software Quality and Safety 2025” report provide a roadmap for navigating this new reality, emphasizing the need for integrated strategies that balance software quality, speed, and security.

Join our LinkedIn group Information Security Community!

No posts to display