AI turns patches into working exploits in 30 minutes, and the 90-day disclosure window is the casualty
90 days isn't enough anymore. AI can turn security patches into working exploits in 30 minutes—and the industry's disclosure window is already broken.

Why it matters
AI's ability to rapidly weaponize patches creates a critical governance gap: the traditional 90-day vendor disclosure window, designed for human researchers, is now obsolete. This forces a reckoning on coordinated disclosure policy and enterprise security strategy.
The key facts
4 to knowLLMs can generate working exploits from patches in 30 minutes
Traditional 90-day disclosure window no longer adequate for AI-accelerated threat landscape
Veteran security researcher calling for policy change
Established disclosure process under threat
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: Language models find security flaws faster and turn patches into working exploits in minutes. A veteran researcher says the established disclosure process needs to change.