WorkThe story, in brief

AI finds plenty of security flaws, but almost none of them get exploited

1.3%. That's the exploit rate for AI-discovered vulnerabilities — same as human-found flaws, but threats are landing 40 days faster.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI is scaling vulnerability discovery but not creating a new exploit vector; however, the acceleration in time-to-exploit signals that defenders need to rethink patch velocity and prioritization in an AI-augmented threat landscape.

The key facts

7 to know
  1. 1,061 AI-discovered vulnerabilities in H1 2026

  2. 14 confirmed exploits (1.3% exploitation rate)

  3. Exploitation rate matches human-discovered vulnerabilities

  4. Median time-to-exploit dropped from 120 days to 80 days

  5. Data source: VulnCheck

  6. 1.3% matches overall vulnerability exploitation baseline

  7. 40-day acceleration in attack velocity on AI-discovered flaws

Go to the source

The Decoderthe-decoder.com

Publisher excerpt: VulnCheck counted how often security flaws found by AI actually get exploited. Out of 1,061 AI-discovered vulnerabilities in the first half of 2026, just 14 saw confirmed attacks. That's 1.3 percent, the same rate as vulnerabilities overall. But exploits are landing faster, with the median dropping…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work