Enterprise security teams have spent the last two years building the case for AI-assisted tooling on the assumption that faster discovery means better defence. The logic is intuitive: find vulnerabilities before attackers do, patch them faster, and reduce exposure windows. What that framing misses is that the same capability lowering the cost of discovery for defenders is lowering it equally for attackers. Google's Threat Intelligence Group reported that the number of exploited zero-days disclosed in 2023 reached 97, nearly double the prior year's figure, and that exploitation rates have tracked closely behind disclosure rates rather than falling away from them. The net defensive gain that most AI security vendors are selling is real in absolute terms, but it is smaller than the pitch suggests once you account for what is happening on the other side of the equation.
Companion piece to our broader work on AI-driven vulnerability economics. See The AI Vulnerability Debt Accumulating in Your Patch Queue for analysis of how CVE generation is outpacing patch cycles and what engineering leaders must do now.
The Symmetry Problem Nobody Is Pricing In
The core issue is not that AI security tooling fails to work. It is that the same underlying capabilities, large-scale code analysis, pattern recognition across vulnerability classes, and automated proof-of-concept generation, are accessible to threat actors at roughly the same cost as they are to defenders.
When a vendor demonstrates that their platform can scan a 10-million-line codebase and surface memory corruption bugs in hours, that is a genuine capability improvement. But the same class of model, fine-tuned on public CVE data and open-source exploit repositories, can do the same job in the opposite direction. The asymmetry that historically favoured defenders, because finding a bug is harder than patching one, is narrowing.
Budget decisions that treat AI security tooling as a straightforward multiplier on defensive capacity are therefore underpricing attacker-side adoption. A more accurate model accounts for the fact that each improvement in automated discovery compresses the window between disclosure and weaponisation, not just the window between introduction and discovery.
What the Disclosure Data Actually Shows
Google's GTIG data on zero-day exploitation is the most direct evidence we have of this dynamic playing out at scale. The near-doubling of exploited disclosures between 2022 and 2023 is not explained by a sudden deterioration in software quality. It reflects a structural shift in the economics of vulnerability research on both sides.
What is particularly significant is the composition of exploited vulnerabilities, not just the count. The proportion of exploited bugs affecting enterprise-grade infrastructure, network edge devices, security appliances, and identity platforms, has grown relative to consumer software. Attackers are concentrating AI-assisted discovery on targets where successful exploitation has the highest downstream value. That is a rational allocation of a newly cheap resource.
For CTOs, this means the risk profile of your estate is shifting toward consequential vulnerabilities in infrastructure components that are often harder to patch quickly and carry longer exposure windows than application-layer bugs. Volume metrics on CVEs discovered tell you relatively little about this shift. Exploitation concentration data tells you considerably more.
The Autonomous Repo Scanning Trade-Off
Several platforms now offer continuous, autonomous scanning of internal repositories, flagging vulnerabilities as code is committed rather than waiting for periodic audits. The operational value is real. Catching an injection vulnerability at commit time is materially cheaper than catching it in production.
The trade-off that does not appear in vendor documentation is what happens when those scanning pipelines are misconfigured, over-permissioned, or compromised. An autonomous scanner that has read access to your entire codebase, including infrastructure-as-code, secrets management configurations, and internal API contracts, is itself a high-value target. Attackers who compromise the scanner gain a pre-indexed map of your attack surface.
This is not a reason to avoid autonomous scanning. It is a reason to treat the scanner's own access model, authentication, secret handling, and egress controls, with the same rigour you would apply to any privileged internal system. Most enterprises deploying these tools in 2026 have not done that work.
Where AI Tooling Genuinely Moves the Needle
The clearest defensive gains from AI-assisted security are in triage and prioritisation rather than raw discovery. A platform that reduces analyst time spent on false positives by 60 percent is delivering a compounding return, because analyst capacity is genuinely scarce and does not scale with the CVE feed.
Similarly, AI-assisted patch impact analysis, predicting which dependency updates will break downstream services before they are applied, addresses a real bottleneck in enterprise patch cycles. The reason critical patches sit undeployed for weeks is rarely that teams do not know about the vulnerability. It is that the cost and risk of deploying the fix in a complex environment is poorly understood until it is too late.
The honest framing for AI security investment in 2026 is that it accelerates the work your analysts are already doing, rather than replacing the judgement those analysts apply. Tools that are positioned as autonomous replacements for security engineering capacity tend to introduce the over-permissioned scanner problem described above without delivering the claimed reduction in headcount.
A More Useful Framework for Investment Decisions
Before committing budget to an AI security platform, three questions are worth answering with specificity rather than accepting vendor benchmarks.
First, what is the platform's own attack surface, and how does it compare to the attack surface reduction it claims to deliver? A scanner that requires broad read access to production infrastructure should be evaluated against the risk it introduces, not just the risk it finds.
Second, does the platform improve exploitation-rate metrics or only discovery-rate metrics? Discovery volume is easy to report. Whether discovered vulnerabilities in your highest-value systems are being remediated faster than they are being weaponised externally is a harder question, and the more relevant one.
Third, what is the attacker-side adoption trajectory for the same underlying capability? If a model architecture or training approach is available open-source, your threat model should assume adversarial use within a short time horizon. Defensive advantage from proprietary tooling is real but time-limited in a way that most security investment cases do not account for.
AI-assisted security tooling is worth deploying. The investment case is most durable when it is built on triage efficiency, analyst augmentation, and patch prioritisation rather than on the assumption that discovery speed alone translates to a reduced exploitation rate. The data suggests that assumption has not held for the past two years, and the structural conditions producing that outcome have not changed.
Where Vector Labs Fits
We help engineering teams build AI systems that operate with appropriately scoped access and auditable decision logic, which matters as much in security tooling as in any other production context. In our vulnerability risk analysis, we examined the gap between AI-driven CVE volume and actual exploitation rates, providing security leaders with a prioritisation framework grounded in real attack surface data rather than disclosure counts. If you are evaluating AI security tooling investment and want an independent view of the trade-offs, contact us at vector-labs.ai/contacts.
FAQs
Yes, but the investment case needs to be built on the right metrics. The strongest returns come from triage efficiency and patch prioritisation, where AI reduces analyst time on low-signal noise and improves remediation sequencing. Those gains are real and do not depend on maintaining a discovery advantage over attackers. Where the case becomes weaker is when platforms are positioned as autonomous replacements for security engineering judgement, because that framing tends to produce over-permissioned deployments that introduce new risk rather than reducing it.
Ask for exploitation-rate data alongside discovery-rate data. A platform that surfaces 40 percent more vulnerabilities is only delivering value if those vulnerabilities are being remediated faster than they are being exploited externally. Most vendor benchmarks report discovery volume because it is easier to measure. The more useful question is whether the platform improves your mean time to remediation on high-severity findings in your most critical systems, and whether that improvement outpaces the compression in exploitation windows that AI is producing on the attacker side.
Least privilege, with explicit boundaries around infrastructure-as-code, secrets management systems, and internal API specifications. Autonomous scanners should be treated as privileged internal systems with their own threat model, not as passive read-only tools. That means reviewing authentication mechanisms, auditing egress behaviour, and rotating any credentials the scanner holds on the same schedule as your other privileged access. The scanner's own security posture should be part of the vendor evaluation process, not an afterthought after deployment.
Because AI-assisted discovery has lowered the cost of finding bugs across large codebases, attackers are rationally concentrating effort on targets where successful exploitation has the highest downstream value. Network edge devices, security appliances, and identity platforms sit in front of large numbers of downstream systems, so a single exploited vulnerability in one of those components can provide access that would otherwise require compromising many individual applications. AI makes it economically viable to conduct that concentrated research at a scale that was previously only accessible to nation-state actors.
There is no reliable universal figure, but the relevant signal is the open-source availability of the underlying model architecture and training data. When a capability is built on a proprietary dataset with no public equivalent, the advantage window is longer. When it is built on a fine-tuned open-source model trained on public CVE and exploit data, the assumption should be that adversarial adoption is already underway. Investment cases that project multi-year defensive advantage from AI tooling should be stress-tested against the realistic attacker-side adoption timeline for the same underlying approach.

