# CodeQL: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 26 judge labels across 1 categories by 11 of 12 models. Page: https://it-ai-index.com/vendors/codeql/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Static application security testing | 2% | 6 | 8% | 26 |

## What the models said for it

- "Look for modern alternatives - Tools with semantic analysis (like CodeQL) show lower false positive rates" (Kimi K2, SAST)
- "the best default choice is usually GitHub CodeQL if your code is already on GitHub" (GPT-5.4 mini, SAST)
- "Prioritize reachability/taint analysis (CodeQL, Veracode <1-10% FP tuned)" (Grok 4.1 Fast, SAST)
- "Powerful semantic analysis, backed by GitHub/Microsoft... Best for: Teams already using GitHub" (Kimi K2, SAST)

## And against it

- "CodeQL is powerful, but Checkmarx notes it requires expertise to write queries" (Perplexity Sonar, SAST)
- "no steep query-DSL learning curve like CodeQL" (DeepSeek V4 Flash, SAST)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
