VYPR
advisoryPublished Oct 8, 2026· 1 source

Insignary Clarity AIR Targets Undeclared Open-Source and AI-Generated Code

Insignary has released Clarity AIR, a new tool designed to scan source code directly and identify open-source and AI-generated code that developers may not have declared in manifests or SBOMs.

Insignary Inc. has announced the general availability of Insignary Clarity AIR, a new source-code scanning product aimed at addressing a critical gap in software supply chain security: undeclared components. The tool performs snippet-level analysis to detect open-source code and AI-generated code that developers might not have included in their official manifests or Software Bills of Materials (SBOMs).

Traditional SBOMs are built upon declared dependencies, but this approach leaves significant blind spots. It's estimated that a substantial majority of modern applications rely heavily on open-source code, much of which can enter a project through unmonitored channels. This includes code snippets copied from forums, functions borrowed from other projects, or, increasingly, code generated by AI coding assistants that may not be meticulously reviewed or declared.

Clarity AIR tackles this challenge by moving beyond manifest analysis to examine the source code directly. It leverages Insignary's fingerprint database of the open-source ecosystem to identify components, even when the code has been modified, adapted, or regenerated. This capability is particularly crucial for detecting AI-assisted code, which often undergoes such transformations.

The product also introduces a novel approach to identifying AI-written code. It classifies code line by line, assigning a confidence score to AI-generated content. This allows security, engineering, and legal teams to treat AI-produced code as a distinct risk category, rather than an invisible or unmanaged element within the codebase.

Furthermore, Clarity AIR aims to provide an "AI Bill of Materials," cataloging the AI models, APIs, and frameworks that software depends on. This offers a more comprehensive view of the software's dependencies, including those related to AI integration. Insignary emphasizes that all matches are human-reviewed and confirmed before being counted, ensuring accuracy and auditability.

The launch of Clarity AIR comes at a time of increasing regulatory pressure. In the U.S., the OMB's Memorandum M-26-05 requires federal agencies to independently verify vendor SBOMs, while the FDA's Section 524B imposes binding requirements for cyber device submissions. Canada's Critical Cyber Systems Protection Act also introduces phasing supply-chain obligations. These evolving compliance landscapes highlight the fragility of relying solely on declared dependencies.

Clarity AIR complements Insignary's existing Clarity suite, which includes Clarity (binary-level software composition analysis) and Clarity SC (SBOM governance). This expanded offering provides end-to-end coverage from source code to compiled binaries and SBOM lifecycle management.

Clarity AIR is available immediately through Insignary and its partner channel, deployable on customer-owned infrastructure. Trial licenses and a free demo of the AI code detection capability are available upon request.

Synthesized by Vypr AI