AI Finds the Bugs in Hours. Fixing Them Still Takes Months.

Artificial intelligence is now fast enough to discover serious security flaws in widely used software within hours. The human systems needed to patch those flaws haven't come close to keeping pace, and the gap is growing.

ThreatVectr Newsdesk· 4 min read
A server rack bathed in cool blue light inside a dark data center, with a single glowing amber warning indicator on one unit, sharp focus on the rack face with
Share

Key points

  • AI tools can now produce security vulnerability reports in hours, work that previously took skilled researchers weeks or months.
  • One in four malicious data breaches in 2025 were AI-enabled, a 56% rise on the previous year, according to IBM's Cost of a Data Breach Report 2026.
  • AI-enabled breaches cost companies an average of $6 million, roughly $1 million above the overall breach average.
  • Only 18% of organisations are using AI to help manage vulnerabilities, even as more than half already use it for detecting attacks.
  • A new EU law, the Cyber Resilience Act, is tightening deadlines for reporting flaws, putting companies in a bind as AI delivers more findings, faster.

For decades, finding a serious security flaw buried inside widely used open-source software (free, publicly available code that powers most of the internet) was slow, specialist work. A skilled researcher might spend weeks or months tracking down a single problem before carefully reporting it to the people responsible for the code.

That timeline has effectively collapsed.

AI tools built on today's most powerful models can now produce detailed vulnerability reports in hours. That is not a distant forecast. It is what the open-source security community has watched happen since late 2024.

So why aren't we safer?

Discovery was never the hard part. Fixing things is.

When a flaw is found, someone still has to read the report, confirm it is real, write a fix, test it, and release an update. Many open-source projects are maintained by volunteers working in their spare time. None of that human work has sped up to match the AI pace. IBM's Cost of a Data Breach Report 2026 puts a number on the resulting pain: one in four malicious breaches last year were AI-enabled, up 56% on the year before, costing companies an average of $6 million each.

Meanwhile, only 18% of organisations are using AI to help manage and patch vulnerabilities, even though more than half already use it to spot attacks coming in.

The criminals are not waiting. Open-weight AI models (models whose inner workings are publicly available, making them free to download and modify) have closed much of the quality gap with expensive commercial systems. That openness is useful for defenders who want to study and steer a model. It also makes capable AI tools available to attackers at almost no cost.

What needs to change?

Two things, mainly: coordination and support for the people doing the work.

Right now, several organisations can independently scan the same obscure code library and each file a separate report without telling each other. The volunteer maintainer receives a flood of overlapping disclosures with no context, no priority order, and no help. Burnout follows. Initiatives like Project Akrites are trying to fix this by verifying findings before they land, giving maintainers the context they need, and timing public disclosure so a patch reaches everyone who depends on a package at the same moment the flaw is announced.

Companies that build products on open-source code (which is most companies) could also do more to fund the upstream projects they depend on. Fewer under-resourced maintainers means fewer drowning in AI-generated reports.

Adding urgency is the EU Cyber Resilience Act, a European law requiring manufacturers who sell to EU customers to report vulnerabilities quickly or face significant fines. AI is delivering more findings, faster, against a regulatory clock that does not slow down.

None of this argues for slowing AI-assisted security research. It argues for building the coordination, staffing, and standards that let the industry actually absorb what that research produces.

Finding problems faster only helps if fixing them gets faster too.

Metric Figure Period
Share of malicious breaches that were AI-enabled 25% (1 in 4) 2025
Year-on-year rise in AI-enabled breaches 56% 2024 to 2025
Average cost of an AI-enabled breach $6 million 2025
Premium over average breach cost ~$1 million 2025
Organisations using AI for vulnerability management 18% 2025

Common questions

Does this affect software ordinary people use every day?

Yes. Open-source code runs inside banking apps, hospital systems, online shops, and government websites. A flaw left unpatched because a volunteer maintainer is overwhelmed is a flaw that criminals can exploit.

Should I do anything right now?

Keep your devices and apps updated; patches for known flaws are your main protection. If a company you use announces a data breach, change your password for that service and switch on two-step verification (where the site texts you a code as a second check) if you have not already.

© 2026 Threat Vectr