Society & Ethics

AI is finding twice as many software flaws. Almost none get exploited.

· July 28, 2026
AI is finding twice as many software flaws. Almost none get exploited.

What happened

AI tools discovered software vulnerabilities at around twice the rate recorded last year. The US National Vulnerabilities Database logged 45,207 flaws between January and July 27. That number nearly matches the total for all of 2025, which itself was a record year. If this pace holds, 2026 will see roughly double the total from 2025. Despite this surge in AI-discovered issues, exploitation of these weaknesses remains minimal so far.

Why it matters

The faster pace of vulnerability detection driven by AI puts pressure on security teams to process and prioritize a larger volume of findings. More flagged issues can improve overall software safety, but only if organizations can vet and patch them efficiently. Meanwhile, the low exploitation rate means attackers are not currently turning these AI-identified flaws into widespread real-world threats. This disconnect highlights a gap between identification and actionable risk, which buyers, operators, and defenders need to factor into risk assessments and resource allocation.

AI’s scanning power is exposing code problems at a speed that outpaces human review capacity. This could raise costs for software makers who must analyze more flagged vulnerabilities, raising operational burdens. Investors and customers should demand stronger processes that separate true risks from noise. The current low exploitation rate also slows attacker incentives to rush weaponizing these flaws, slightly easing immediate external threat pressure.

What to watch next

The key factor is whether exploitation pressure picks up in 2026. If attackers start weaponizing the increased pipeline of AI-discovered vulnerabilities, it would shift security priorities toward faster, smarter patching and more automated response tools. Watch how vulnerability management vendors adapt their platforms to handle rising volume while reducing false positives. Also track how software producers balance investment in fixing AI-flagged issues against business impact and risk tolerance.

Regulators and compliance bodies may tighten standards as AI finds vulnerabilities faster, forcing companies to accelerate disclosure and remediation timelines. For operators, the crucial challenge will be integrating AI alerts meaningfully without shortening breach detection or response windows. The unfolding tension between AI-driven detection speed and real-world exploitation will shape security budgets, vendor strategies, and cyber insurance pricing in the year ahead.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.