TECH
Artificial intelligence has accelerated system protection but created a bottleneck
For decades, discovering a serious software vulnerability required weeks of investigation, highly specialized professionals, and often a good deal of luck. This landscape has changed radically with the advancement of artificial intelligence. Today, automated systems can analyze millions of lines of code in just a few days and identify issues that would have previously gone unnoticed. However, this evolution has brought an unexpected consequence that is beginning to worry cybersecurity experts worldwide.
The digital security sector is undergoing an unprecedented transformation. AI-based tools are identifying vulnerabilities at such a high speed that the teams responsible for remediation are struggling to keep pace with this new tempo.
The latest figures clearly illustrate this shift. Major technology companies have recorded significant growth in the number of flaws patched in their flagship products, indicating that the capacity to detect issues has evolved much faster than traditional software update processes.
One of the most notable examples involves Microsoft. After recording a record number of patches in June 2026, the company surprised the industry again just a month later by releasing an even larger update; this included hundreds of vulnerability fixes—dozens of which were classified as critical—and addressed several flaws that had been exploited before the updates were even made available.
This trend was not limited to a single company. Widely used web browsers and enterprise platforms also saw historic increases in the number of vulnerabilities identified in their codebases.
While automated analysis tools have existed for years, the recent surge occurred because AI models have moved beyond simply testing random data combinations. They can now understand how the code functions, establish relationships between different parts of the system, and predict how minor flaws might be combined to launch more sophisticated attacks.
In practice, tasks that once relied exclusively on highly experienced researchers are now being performed at scale by AI models specifically trained for this purpose. The volume of discoveries is impressive, yet it creates a new bottleneck for the entire industry... The impact of this advancement has been evident in several major projects. The Google Chrome browser, for instance, saw the number of vulnerabilities patched in just two versions exceed the total identified over the preceding two years.
According to the company, artificial intelligence played a decisive role in this surge, significantly accelerating the flaw-identification process. Consequently, Chrome began testing an even faster pace for rolling out security updates to reduce the time between discovering a problem and fixing it.
A similar situation unfolded with Firefox. Following successful experiments using models developed by Anthropic to locate significant vulnerabilities, Mozilla expanded its use of these tools and uncovered hundreds of new issues in a single browser version.
Companies like Oracle also recorded a substantial increase in the number of patches released for their products. Most of these vulnerabilities were identified through internal analysis, reinforcing the trend of using artificial intelligence as a key ally for security teams.
However, there is an important detail that prevents alarmist interpretations: not all vulnerabilities pose the same level of risk. Amidst thousands of published patches, only a relatively small fraction represents truly critical threats to companies and users.
Even so, this avalanche of discoveries creates a new operational challenge.
Finding the flaws is no longer the problem; the challenge now is deciding what to fix first... As artificial intelligence exponentially increases the number of discovered vulnerabilities, system administrators face an increasingly complex task: setting priorities.
Each update requires careful analysis before installation. In corporate environments, applying hundreds of patches without a plan can lead to incompatibilities, critical system outages, and operational impacts just as significant as the flaws they aim to fix.
Consequently, security teams must assess which vulnerabilities pose the highest risk of immediate exploitation, which can wait for a scheduled maintenance window, and which have a negligible impact on a specific infrastructure.
This process demands technical expertise, testing, and planning—activities that still rely on human experience, even with the growing role of artificial intelligence.
The current landscape reveals a significant shift in the cybersecurity sector. For years, the primary challenge was uncovering vulnerabilities hidden within millions of lines of code. Technology has now largely resolved that issue.
The new hurdle lies in managing an ever-expanding volume of information. While the risk used to be overlooking flaws, the challenge today is transforming thousands of findings into effective patches without compromising system stability.
Paradoxically, the more efficient artificial intelligence becomes at hunting for vulnerabilities, the greater the responsibility placed on human teams to decide how, when, and which issues truly need to be addressed first.
mundophone



