TechRadar News.
Technology

Insignary Launches Clarity AIR to Detect Undeclared Open‑Source and AI‑Generated Code

Insignary Launches Clarity AIR to Detect Undeclared Open‑Source and AI‑Generated Code

On October 8, 2026, Toronto‑based security company Insignary made public the general availability of Clarity AIR, a scanning tool intended to uncover open‑source elements and AI‑produced code that developers have omitted from their software bill of materials.

Working at the snippet granularity, Clarity AIR examines every line of a codebase and cross‑references it with catalogued open‑source libraries and signatures characteristic of machine‑learning code generators. If it discovers a correspondence that isn’t listed among the project’s declared dependencies, the solution marks that fragment for inspection, providing security and compliance groups with a transparent picture of concealed risk.

Demand for this functionality has risen in step with two concurrent developments: the rapid surge in use of third‑party open‑source components and the growing dependence on AI helpers like Copilot and Claude for producing production‑grade code. Though both speed up development, they create a “blind spot” in which untracked code may infiltrate applications, risking license breaches or hidden vulnerabilities that conventional static analysis tools might miss.

Analysts point out that current software composition analysis (SCA) tools generally target declared dependencies, rendering undeclared snippets unseen. By hooking straight into CI pipelines and accommodating popular CI/CD platforms, Clarity AIR is designed to augment—not supplant—existing SCA and static application security testing (SAST) offerings. Initial users in finance and health‑tech report that the product uncovered previously hidden GPL‑licensed code and AI‑generated functions that were missing proper attribution.

Insignary states that Clarity AIR will be available via a SaaS subscription model, with tiered rates determined by the size of the codebase and the frequency of scans. The firm also teased upcoming features such as automated remediation advice and broader language coverage beyond the initial Java, Python, and JavaScript support. As companies wrestle with the intricacies of contemporary software supply chains, solutions that bridge the divide between declared and real code are poised to become a staple of DevSecOps toolsets.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related