Microsoft says AI is finding so many Windows bugs, expect bigger Patch Tuesdays
The company is using multiple AI models to hunt vulnerabilities in Windows code, and warns customers will see more fixes each month as a result.

Key points
- Microsoft said AI-driven scanning is uncovering more Windows security flaws, and customers should expect larger monthly updates.
- The company runs MDASH, which uses several AI models together to find and verify possible bugs in critical Windows files.
- Human engineers review every proposed fix before it ships.
- Reuters reported two days earlier that CISA has started using Anthropic's Fable model to audit government software.
Microsoft has an unusual warning for Windows users: Patch Tuesday is getting busier.
In a blog post published this week, the company said its engineers are using artificial intelligence to hunt through Windows code for security flaws, and the AI is finding a lot of them. Monthly security updates, known as Patch Tuesday, will likely contain more fixes than before.
"The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code," Microsoft said.
That's a good problem to have, mostly.
What is Microsoft actually doing?
The company runs a tool it calls MDASH, short for Microsoft Security's multi-model agentic scanning harness, a system that points several AI models at the most important pieces of Windows code, asks each to look for weaknesses, then cross-checks their answers.
A second stage, built specifically for Windows, weeds out false alarms before a human engineer sees the report. Only after that filter does a real person examine the bug and write a fix.
Microsoft was firm on that last point: every proposed code change is reviewed by a human before it reaches customers. The AI suggests. Engineers decide.
The company's also using AI to help staff work faster, covering failure analysis, patch proposals and hunting for the same mistake repeated elsewhere in the codebase. If you've ever fixed one bug only to find copies of it hiding in nearby files, you get the appeal.
Should ordinary users be worried by bigger updates?
No, and the opposite is closer to the truth. More fixes in a Patch Tuesday release means more holes closed before criminals find them. A zero-day, meaning a flaw the software maker didn't know about, is dangerous precisely because there's no patch yet. Finding these bugs internally is the whole point.
For home users and small businesses, the practical advice is unchanged: let Windows Update run, and don't sit on a pending restart for weeks. If Microsoft ships more fixes, ignoring them is a worse bet than it used to be.
For IT teams the message is sharper. Testing and rolling out a heavier monthly patch load is real work, and that load is going up.
The other side of the coin
Microsoft was careful to note that criminals are using AI too. So the company is updating its Secure Development Lifecycle, the internal rulebook for how Windows gets built, to account for AI-assisted attacks and to pull AI checks earlier into development.
This isn't happening in isolation. Two days before Microsoft's announcement, Reuters reported that CISA had started running Anthropic's Fable model over federal software to find exploitable flaws. Officials said the audits had already turned up vulnerabilities, though they wouldn't say how many or how serious. We covered CISA's move on 7 July in our earlier report on the agency's AI scanning push, though that story named a different tool: Anthropic's Mythos, not Fable.
Adobe ran into the same pressure from a different angle. As we reported on 3 July, faster vulnerability discovery is already forcing companies to double their patch cadence.
Defenders and attackers are both pointing AI at the same job: reading code and looking for cracks. For now, defenders have the home advantage on their own source tree.
Whoever ships fixes fastest wins the month.



