Can You Still Patch Your Way to Safety? Why the Old Playbook Is Breaking Down
Artificial intelligence can now turn a published vulnerability description into a working attack in under a day. That changes the math for every organisation relying on traditional patch schedules.

Key points
- AI tools can generate a working exploit, meaning a ready-to-use attack built from a software flaw, within roughly 20 hours of a vulnerability being publicly described.
- Traditional patch management, where IT teams test and apply software fixes on a weekly or monthly cycle, assumes attackers need days or weeks to act on new flaws.
- That assumption no longer holds, and the gap between a flaw being announced and criminals using it is shrinking fast.
- Organisations of every size need to rethink how quickly they prioritise and apply fixes.
What is actually changing here?
For years, security teams operated on a simple idea: a software flaw gets disclosed, researchers publish details, attackers slowly figure out how to use it, and IT teams patch the system before anything bad happens. That window of relative safety is closing.
AI, specifically the kind of large language model, or conversational AI system, now used widely in software development, can read a public description of a vulnerability and produce a working exploit in roughly 20 hours. SecurityWeek flagged this figure in a recent opinion piece, and it lines up with what several CTI, meaning cyber-threat intelligence, researchers have been observing in the wild for months.
Twenty hours is not long. Many organisations patch on a monthly cycle. Some take longer.
Why does this matter for ordinary people?
When a company's software gets attacked through an unpatched flaw, the people who feel it are customers and staff, not the IT team.
A hospital running outdated systems could see patient records locked. A retailer could lose payment data. A school could find its admin systems frozen mid-term. The breach always starts somewhere technical, but the consequences land on real people.
The core problem is that defenders, the people responsible for fixing software, are still working at human speed. Attackers using AI tools are not.
So is patching pointless now?
No. Patching still matters. But patching alone, on a slow schedule, is no longer enough protection.
Security teams have traditionally sorted flaws by severity scores, queuing the worst ones first and working down the list. That approach made sense when attackers needed weeks to build a working exploit. If an AI tool can do it overnight, a flaw that looked medium-priority on Monday could be actively weaponised by Tuesday.
What this points toward is a shift in emphasis: faster patch cycles for internet-facing systems, better monitoring to catch attacks that slip through before a patch is available, and a harder look at which systems truly need to be connected to the internet in the first place.
For anyone running a business, even a small one, the practical takeaway is straightforward. Check whether your software vendor offers automatic updates. If they do, turn them on. If your IT team manages updates manually, ask how long the gap typically is between a patch being released and it being applied. That gap is the window attackers are aiming for.
Common questions
Do I need to do anything right now?
If you run automatic updates on your devices and software, you are already doing the most important thing. If updates are managed manually by an IT team, ask them about their patching timeline and whether critical fixes get rushed through ahead of the normal schedule.
Is AI making hackers genuinely more dangerous?
Yes, in this specific way. AI does not make criminals smarter, but it removes some of the technical skill and time that previously slowed them down. A flaw that once required an expert to turn into an attack can now be turned into one much faster and by people with less expertise.



