Our AI strategy for preemptive security
In a recent Bugcrowd webinar, CEO Dave Gerry and Chief AI and Science Officer David Brumley sat down to tackle one of the most pressing questions facing security teams right now: is the explosion of AI-driven vulnerability discovery a crisis, a tool, or both?
The answer, they agreed, is nuanced, but the urgency is not. Watch the full session on-demand, or check out the quick summary below.
AI is genuinely accelerating vulnerability discovery. Foundational model companies are finding zero-days in the Linux kernel at rates that would have been impossible even a year ago. But the raw volume of findings is creating its own problem: a rising signal-to-noise ratio as unvalidated results flood security teams.
“What we’re seeing is a lot of people use AI to find vulnerabilities, but they don’t validate them, and then they turn out to be what we would call slop,” David Brumley said.
The models have improved dramatically. What once required heavy prompt engineering and constant human guidance can now run with a security professional monitoring from outside the loop. Humans are still necessary, but no longer hands-on at every step.
The numbers that should concern every security leader illustrate just how dramatically the window to respond to a vulnerability has shrunk.
“While the ceiling for the best hackers has ben raised as they can now operate at a much higher scale, the floor and the barrier to entry has also been significantly lowered, where you can have very unsophisticated attackers running very sophisticated attacks in an incredibly short window,” David Gerry said.
Gerry framed the challenge for organizations in two distinct areas. First, understanding the new attack surface. Shadow AI is the new shadow IT. Employees are using unapproved models, feeding company data into external tools, and shipping AI-generated code without IT’s knowledge. CISOs need an accurate inventory of what AI is in use and what data it can access.
Second, prioritization. Volume without context is noise. A critical-severity finding doesn’t automatically warrant more attention than two mediums that can be chained into a more damaging exploit. Security teams need frameworks and tooling that can reason across findings, not just rank them by CVSS score.
“I don’t care where a vulnerability is detected from, whether that was from automation, whether that was from a traditional AppSec platform, whether that was from a human hacker or from AI. I just wanna know that the vulnerability was detected before a bad actor found it,” Gerry said.
AI patching is not keeping pace with AI exploitation. Brumley pointed to the DARPA AI Cyber Challenge as evidence; AI-generated patches tend to be localized spot fixes rather than the more systemic remediations a human engineer would implement.
The prescription isn’t to wait for AI patching to catch up—it’s to use AI defensively at the same rate attackers are using it offensively. That means giving security teams AI-powered prioritization that can reason across all their inputs: bug bounty findings, pen test results, red team reports, SAST, and more.
Both Gerry and Brumley pushed back on the narrative that AI is replacing security researchers. The most productive framing, they argued, is augmentation: giving skilled hackers the ability to scale their methodologies, automate their tooling, and work at machine speed.
“This is a Crowd and AI story. This isn’t about one replacing the other. It’s how we combine the two and start to put machine speed behind a human hacker,” Gerry said.
When hacker-validated findings increase in volume, as they inevitably will, the real need is a layer that can take that flood of data and surface the two or three actions that cut off the most attack paths for a given organization.
Brumley characterized the current moment not as an incremental change but as a genuine disruption—one that demands a full rewrite of the defender’s rulebook. The regulatory environment is fragmented and lagging, with states moving independently and national standards still absent. Organizations can’t wait for clarity from above; they need to act now on inventory, prioritization, and AI-assisted response.
The teams that will come out ahead are those treating this not as a technology problem to solve once, but as an ongoing operational posture, continuously adapting as the models improve and the attack surface expands.
If you found this summary interesting, check out the whole session on-demand.