AI Detects Too Many Bugs for Humans to Keep Up

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
AI and Rapid Vulnerability Detection
In the field of cybersecurity, artificial intelligence (AI) has revolutionized the way security flaws are discovered. It is capable of detecting vulnerabilities at an unprecedented pace, far surpassing human capabilities. However, this speed has a downside: AI can introduce up to nine times more new vulnerabilities than human developers when it attempts to fix these flaws.
Challenges Posed by AI in Security
The rapid increase in security issues identified by AI is concerning. Whether on personal computers or in data centers, no one is immune to this wave of discoveries. While AI is effective at highlighting these flaws, the challenge lies in companies' ability to address them. Even giants like Google can manage a large number of fixes, but most companies do not have the same resources.
Apple, for instance, has had to limit the number of bug reports that researchers can submit, as it cannot keep pace with the rate set by AI. This saturation means that even critical vulnerabilities can be sidelined if they exceed the monthly quota.
A Worsening Problem
AI has accelerated the pace of bug reports, but it has also widened the gap between machine detection and human capacity to process this information. Developers and security teams are overwhelmed by the volume of data, making it difficult to distinguish between exploitable issues and the noise generated by machines. System administrators and Chief Information Security Officers (CISOs) struggle to keep up with the necessary updates.
Traditional Security Methods Under Scrutiny
Historically, security teams managed a workflow where critical bugs were identified and prioritized for fixing. Common Vulnerabilities and Exposures (CVE) scores guided these decisions. However, AI has disrupted this approach by making defect discovery much more frequent and less costly. For example, during Microsoft's Patch Tuesday in July 2026, a total of 570 patches were released, including three zero-days, setting a record that reflects the growing pressure on security teams.
Companies Facing a Dilemma
Companies find themselves in a delicate situation, trying to benefit from rapid vulnerability detection while minimizing unnecessary noise. AI can indeed identify real issues earlier, but it also generates reports that require validation, diverting security teams' attention from essential fixes.
Why Can’t AI Fix Bugs?
Finding flaws is one thing, but fixing them is another. A study showed that advanced language models (LLMs) used by AI introduce nearly nine times more new vulnerabilities than human developers. These new flaws often exhibit unique patterns that do not exist in the original code.
Proposed Solutions by Google
To address these challenges, Google offers several approaches:
-
Narrow the scope of changes: Instead of asking AI to eliminate a vulnerability, it is advisable to target specific changes, such as updating a particular dependency.
-
Separate remediation from verification: After applying a patch, it is crucial to conduct independent verification using scanners and targeted tests, rather than relying solely on the success of builds and tests.
-
Human review for complex changes: AI can serve as an assistant, but human engineers must oversee complex changes, especially those related to design and authentication.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.