AI finds plenty of security flaws, but almost none of them get exploited
What happened
VulnCheck analyzed 1,061 security flaws discovered by AI tools in the first half of 2026. Only 14 of these AI-identified vulnerabilities saw confirmed exploitation, representing 1.3 percent. This matches the overall exploitation rate for vulnerabilities found by any means. However, exploits are hitting targets faster, with the median time from discovery to exploitation shrinking from 120 days to 80 days.
The risk
AI is uncovering a large number of security issues, but attackers are using only a tiny fraction. The overall risk level from AI-identified vulnerabilities remains aligned with traditional discovery methods. The faster turnaround on exploits means attackers are getting quicker at weaponizing newly found weaknesses, pressuring security teams to accelerate patching and response.
Why it matters
For security teams and operators, AI vulnerability discovery does not translate into more exploited flaws, at least so far. The advantage goes to defenders who can use AI to spot risks earlier and plan mitigations. On the other hand, the shrinking window between discovery and exploitation tightens the operational tempo for fix deployment. This creates a race where defenders must accelerate patch cycles to counter rapidly weaponized exploits.
Who should pay attention
Security operations centers, vulnerability management teams, and incident responders should take note. The data suggests investments in AI detection tools will not overwhelm with exploited attack vectors but will provide earlier warning. The pressure is on response teams to act faster than ever. Investors and technology buyers should weigh AI vulnerability discovery tools with realistic expectations about exploitation rates and response demands.
What to watch next
Monitor if the exploitation rate for AI-found vulnerabilities rises as attackers refine offensive AI capabilities. Also watch how security teams adapt their patching speed and prioritization in response to shorter exploit lead times. The balance of power may shift if attackers close the gap between finding and weaponizing AI-detected issues.
AI Quick Briefs Editorial Desk