From Months to Minutes: How AI Is Forcing Companies to Rethink Software Security
Criminals once needed two years to turn a software flaw into a working attack. By next year, that window is expected to shrink to four hours. Companies that patch on a quarterly schedule are already behind.

Key points
- In 2018, attackers took an average of 771 days to weaponise a known software flaw; by 2026 that figure is projected to fall to roughly four hours.
- AI tools let criminals scan for weaknesses, build attack code, and launch intrusions at a speed that quarterly patching can't match.
- Security experts now recommend continuous scanning and risk assessment, replacing annual or quarterly reviews.
- Companies that can't patch fast enough can still cut their exposure by tightening preventive controls and running formal threat intelligence programmes.
- Customers whose data sits inside affected applications face rising risk if their providers aren't adapting now.
Not long ago, a criminal who found a flaw in a company's software needed more than two years on average to turn it into a working attack. IT teams had a long runway. That's gone.
By 2026, the same process is expected to take around four hours. AI tools that automatically scan thousands of systems and write attack code without human help are the main driver. As we reported on 10 August, AI is already finding thousands of flaws faster than humans can patch them, and that was before the exploitation side of the equation caught up.
Why can't companies just patch faster?
Patching, applying a software update that fixes a security weakness, takes time even in well-run organisations. Code must be tested before it goes live; teams need to co-ordinate across departments. Four hours isn't a realistic patching window for any large company.
Patching alone can no longer be the primary defence. Companies need a broader set of habits running in parallel.
What should companies actually be doing?
Several steps can reduce risk even when patches aren't yet applied.
First, know what you have. A company can't protect software it doesn't know is running. Maintaining an up-to-date inventory of every application, every API (a connection point that lets different pieces of software talk to each other), and every AI component is the foundation everything else rests on.
Second, scan constantly. Vulnerability scanning, running automated checks for known weaknesses across company systems, used to happen quarterly. Given current attack speeds, it needs to run far more frequently.
| Practice | Old standard | New recommendation |
|---|---|---|
| Risk assessment | Annually or quarterly | Continuous |
| Vulnerability scanning | Quarterly | Near-continuous |
| Patching cycle | Months | As fast as possible; hours where critical |
| Threat intelligence | Ad hoc | Formal, ongoing programme |
Third, tighten preventive controls. Firewalls and access restrictions can slow an attacker down even when the underlying flaw hasn't been patched. These are levers security teams can pull when patching isn't yet possible.
Fourth, add runtime security, software that watches an application while it's actually running and raises an alert if something unusual happens. This matters especially as AI components, including large language models (LLMs, the technology behind tools like ChatGPT), become part of company products. The source article also flags agentic AI, autonomous software that can act independently, as an emerging concern: enterprises should add bot protection and continuous monitoring to catch agents that go rogue.
Should ordinary customers be worried?
Yes, in a practical sense. If a company holding your personal data or payment details is still running on a quarterly security review, its exposure is growing every week.
If you receive an unexpected email asking you to confirm account details after a service you use announces a breach, treat it as suspicious. Criminals often follow breaches with phishing emails, fake messages designed to trick you into handing over passwords. Contact the company directly through its official website rather than clicking any link in the email.



