Key takeaways

  • AI is accelerating vulnerability discovery at unprecedented speed — the window from disclosure to exploitation has collapsed from 53 days in 2024 to just 8 hours in 2026, forcing organizations to rethink remediation SLAs and response workflows entirely.
  • Volume without validation is noise — with 82% of hackers now using AI regularly, security teams face a flood of findings that demand an intelligent prioritization layer, not just faster triage. The organizations winning are those who can reason across all their inputs to identify the two or three fixes that cut off the most attack paths.
  • AI augments security researchers; it doesn’t replace them — the most effective security programs are combining human hacker expertise with AI-powered scale, using crowd-validated findings alongside automated discovery to level a playing field that currently favors attackers.

In a recent Bugcrowd webinar, CEO Dave Gerry and Chief AI and Science Officer David Brumley sat down to tackle one of the most pressing questions facing security teams right now: is the explosion of AI-driven vulnerability discovery a crisis, a tool, or both?

The answer, they agreed, is nuanced, but the urgency is not. Watch the full session on-demand, or check out the quick summary below.

Overhyped or real?

AI is genuinely accelerating vulnerability discovery. Foundational model companies are finding zero-days in the Linux kernel at rates that would have been impossible even a year ago. But the raw volume of findings is creating its own problem: a rising signal-to-noise ratio as unvalidated results flood security teams.

“What we’re seeing is a lot of people use AI to find vulnerabilities, but they don’t validate them, and then they turn out to be what we would call slop,” David Brumley said. 

The models have improved dramatically. What once required heavy prompt engineering and constant human guidance can now run with a security professional monitoring from outside the loop. Humans are still necessary, but no longer hands-on at every step.

AI slop by the numbers

The numbers that should concern every security leader illustrate just how dramatically the window to respond to a vulnerability has shrunk.

  • 53 days from disclosure to exploitation in 2024 vs 8 hours time from disclosure to exploitation in 2026
  • 82% of hackers regularly using AI in their workflow

“While the ceiling for the best hackers has ben raised as they can now operate at a much higher scale, the floor and the barrier to entry has also been significantly lowered, where you can have very unsophisticated attackers running very sophisticated attacks in an incredibly short window,” David Gerry said. 

Two buckets every organization needs to address

Gerry framed the challenge for organizations in two distinct areas. First, understanding the new attack surface. Shadow AI is the new shadow IT. Employees are using unapproved models, feeding company data into external tools, and shipping AI-generated code without IT’s knowledge. CISOs need an accurate inventory of what AI is in use and what data it can access.

Second, prioritization. Volume without context is noise. A critical-severity finding doesn’t automatically warrant more attention than two mediums that can be chained into a more damaging exploit. Security teams need frameworks and tooling that can reason across findings, not just rank them by CVSS score.

“I don’t care where a vulnerability is detected from, whether that was from automation, whether that was from a traditional AppSec platform, whether that was from a human hacker or from AI. I just wanna know that the vulnerability was detected before a bad actor found it,” Gerry said.

AI an offense is outpacing AI on defense

AI patching is not keeping pace with AI exploitation. Brumley pointed to the DARPA AI Cyber Challenge as evidence; AI-generated patches tend to be localized spot fixes rather than the more systemic remediations a human engineer would implement.

The prescription isn’t to wait for AI patching to catch up—it’s to use AI defensively at the same rate attackers are using it offensively. That means giving security teams AI-powered prioritization that can reason across all their inputs: bug bounty findings, pen test results, red team reports, SAST, and more.

Humans and AI, not humans vs AI

Both Gerry and Brumley pushed back on the narrative that AI is replacing security researchers. The most productive framing, they argued, is augmentation: giving skilled hackers the ability to scale their methodologies, automate their tooling, and work at machine speed.

“This is a Crowd and AI story. This isn’t about one replacing the other. It’s how we combine the two and start to put machine speed behind a human hacker,” Gerry said. 

When hacker-validated findings increase in volume, as they inevitably will, the real need is a layer that can take that flood of data and surface the two or three actions that cut off the most attack paths for a given organization.

What this means for the road ahead

Brumley characterized the current moment not as an incremental change but as a genuine disruption—one that demands a full rewrite of the defender’s rulebook. The regulatory environment is fragmented and lagging, with states moving independently and national standards still absent. Organizations can’t wait for clarity from above; they need to act now on inventory, prioritization, and AI-assisted response.

The teams that will come out ahead are those treating this not as a technology problem to solve once, but as an ongoing operational posture, continuously adapting as the models improve and the attack surface expands.

If you found this summary interesting, check out the whole session on-demand