Given the fact that Copilot is trained on a corpus of real code, is it not reasonable to assume that the number of security flaws just reflects how insecure most public code is? If human-written code has about the same 40% suffering from security issues then then using Copilot is certainly no worse. It definitely doesn't seem fair to invalidate the idea of AI-assisted code generation without testing that.