Hacker News
Jan Schauma: Finding Thousands of AI-Discovered Vulnerabilities Has Not Made Anyone Safer
Schauma's 16 September 2026 essay argues that AI vulnerability research is solving the wrong problem, since finding vulnerabilities has never been the bottleneck; getting packages updated is. He says he now spends upwards of 75% of his time directly or indirectly dealing with AI and that the engineering hours poured into AI bug discovery could have gone to asset inventory and automated patching infrastructure. His second point is narrower and harder to dismiss: AI-generated patches are increasingly reviewed by AI, leaving the humans on call with steadily less comprehension of systems that are getting more opaque.
↳ Follow the thread