Bugs discovered by AI are not easier to exploit
The idea that bugs discovered by artificial intelligence provide an easy advantage to attackers does not hold true. Despite the hype, the reality is quite different. A study by VulnCheck analyzed over a thousand vulnerabilities discovered with AI assistance and found that less than 2% were actually exploited. This challenges the narrative that cutting-edge models are giving attackers a significant advantage.
The Glasswing project from Anthropic, for example, discovered tens of thousands of potential flaws, but few resulted in actual attacks. VulnCheck's research cross-referenced data from the project with its database of known vulnerabilities and found only 14 cases that were exploited. This is practically the same exploitation rate as vulnerabilities discovered by traditional methods.
The project that challenged expectations
The Glasswing project was launched with warnings that AI-assisted vulnerability discovery could allow attackers to hijack systems and steal data. However, the reality is that AI is more helping researchers find flaws than increasing the rate of attacks. So far, only one vulnerability identified by the project has been confirmed as exploited.
Patrick Garrity, a security researcher at VulnCheck, states that AI-assisted vulnerability discovery has value for both attackers and defenders. He argues that these vulnerabilities are not more likely to be exploited than those found by traditional methods. AI is actually increasing the volume of flaws discovered, giving defenders the chance to fix them before criminals exploit them.
The reality behind the numbers
Meanwhile, attackers are not standing still. In the first half of 2026, VulnCheck identified 495 known vulnerabilities that were exploited, with content management systems and network edge devices being preferred targets. AI products are also becoming increasingly attractive targets as attackers seek weaknesses in the growing stack of AI software.
AI-assisted vulnerability discovery may be changing vulnerability research, but it has not yet produced the exploitation apocalypse that many predicted. AI is helping to find more flaws, but the exploitation of these flaws still depends on other factors. The impact has been real, but modest, and the risk is not imaginary. The reality is that rhetoric has outpaced reality so far, but that does not mean the threat cannot grow in the future.
The evolution of AI in cybersecurity is a constantly changing field. Companies need to stay alert to new discoveries and prepare for a scenario where AI plays an increasingly important role in both defense and attack. What we are seeing is just the beginning of a new era in digital security.





Comments (0)
Comments are moderated and if they violate our Terms and Conditions of use, the comment will be deleted. Persistence in violation will result in a ban of your account.