Editorial illustration for AI tools flag thousands of flaws, but few get weaponized
AI Finds Thousands of Flaws, Few Turn Weaponized
Patrick Garrity spent the first half of 2026 tracking something most vulnerability reports skip: what actually happens after AI tools flag a security flaw. His firm, VulnCheck, counted 1,061 vulnerabilities traced to AI-assisted discovery during that period. Anthropic's Project Glasswing alone generated more than 23,000 findings, whittled down to 126 published entries. Numbers like that suggest AI has turned vulnerability hunting into a volume game, with machines surfacing flaws faster than anyone can review them.
But volume and danger aren't the same thing. Garrity's data asks a narrower question than "how many bugs did AI find." It asks how many of those bugs ever got used in a real attack, and how that exploitation rate compares to vulnerabilities discovered the old-fashioned way. The answer complicates the narrative that AI-discovered flaws represent some new tier of risk. It also reframes what security teams should actually watch for, since raw discovery counts turn out to be a poor guide to where the real threat sits, whether in specific software categories or in the AI tooling itself.
For the first half of 2026, Patrick Garrity counts 1,061 vulnerabilities traced to AI-assisted discovery. Fourteen showed confirmed exploitation. That's 1.3%, roughly the same rate as vulnerabilities overall.
Why this matters
The numbers Garrity is tracking cut against the panic narrative that AI-discovered bugs are handing attackers a loaded gun. Project Glasswing's 23,000 findings collapsing to one confirmed attack tells us the bottleneck was never finding flaws, it was always turning a flaw into a working exploit at scale. For teams building AI-assisted scanning tools, that 1.3% figure is worth internalizing before pitching your product as a threat-hunting breakthrough or a doomsday machine.
Volume of discovery isn't the metric that matters; conversion to exploitation is, and right now AI hasn't moved that needle much beyond historical baselines. The one number that should get attention is the shrinking window, 80 days to first exploitation instead of 120. If AI is compressing that timeline even while leaving the exploitation rate flat, defenders lose their margin for patching before attackers arrive, even without a surge in raw exploit counts.
Researchers publishing vulnerability data should start reporting time-to-exploit alongside discovery counts. Founders selling AI security tools should be asked directly what their product does to that 80-day number, not how many bugs it finds.
Common Questions Answered
How many vulnerabilities traced to AI-assisted discovery were actually exploited in the first half of 2026?
According to Patrick Garrity's tracking at VulnCheck, out of 1,061 vulnerabilities traced to AI-assisted discovery during the first half of 2026, only 14 showed confirmed exploitation. This represents approximately 1.3% of discovered vulnerabilities, which is roughly the same rate as vulnerabilities discovered through traditional methods overall.
What was the outcome of Anthropic's Project Glasswing in terms of published vulnerabilities?
Anthropic's Project Glasswing generated more than 23,000 findings during the tracked period, but this massive volume was significantly reduced to only 126 published entries. This dramatic reduction demonstrates the filtering process between initial AI discovery and actual published vulnerabilities.
Why does the low weaponization rate of AI-discovered vulnerabilities matter for security teams?
The 1.3% exploitation rate reveals that the real bottleneck in security threats is not finding flaws but rather turning a flaw into a working exploit at scale. This insight suggests that AI-assisted scanning tools should be evaluated based on realistic threat potential rather than panic narratives about AI handing attackers loaded guns.
What does Patrick Garrity's research reveal about the volume of AI-assisted vulnerability discovery?
Garrity's research shows that AI has transformed vulnerability hunting into a volume game, with machines surfacing flaws faster than humans can evaluate them. His firm VulnCheck tracked 1,061 vulnerabilities from AI-assisted discovery in just the first half of 2026, highlighting the dramatic increase in discovery speed compared to traditional methods.
Further Reading
- AI-found bugs aren't proving any easier to exploit despite the hype - The Register
- AI Finding Twice as Many Cyber Flaws in 2026 as It Did in 2025 - Claims Journal
- New AI models are pushing open-source security to its limits. Their developers must step up. - Atlantic Council
- AI Hype vs. Reality: Is AI Really Rewriting the Vulnerability Equation? - Recorded Future
- Google: Criminal hackers used AI to find, weaponize software flaw - SignalsCV (syndicated Reuters story)