AI agents now write code that developers approve or reject, creating ambiguity about who is responsible for vulnerabilities—the developer who accepted the code or the AI that generated it. This represents a fundamental shift from the traditional model where developers owned their code and its security implications.