AI is helping discover more vulnerabilities than ever before, but the growing volume of discoveries may make it harder for security teams to identify the flaws that matter most.
Key Takeaways:
A new report from Google Threat Intelligence Group suggests that AI is dramatically accelerating vulnerability discovery, with disclosed vulnerabilities doubling during 2026 and high-risk flaws increasing significantly. The researchers also found that AI-powered tools are identifying a larger share of vulnerabilities that can lead to remote code execution.
The growing volume of discoveries is creating new challenges for security teams already struggling with patch fatigue. This report shows that only a small fraction of disclosed vulnerabilities are actively exploited, but attackers appear to be moving faster to exploit newly disclosed flaws. It also highlights a quickly expanding attack surface around AI infrastructure, including orchestration frameworks, model-serving platforms, and enterprise AI gateways.
Google argues that organizations need to rethink how they manage vulnerabilities in an environment where AI is accelerating both discovery and exploitation. Security teams should prioritize vulnerabilities based on real-world threat intelligence, exploit activity, and business impact. This report notes that only a small fraction of disclosed vulnerabilities are ever exploited, which suggests that a risk-based approach can help organizations focus resources on the threats that matter most.
The researchers also recommend combining threat intelligence with automation to improve response times. Google expects organizations to increasingly rely on automated and agentic remediation capabilities, along with stronger defenses for internet-facing systems, where attackers frequently target high-risk vulnerabilities for initial access.
For organizations adopting AI technologies, this report highlights the importance of securing the AI stack itself. Google found that vulnerabilities are growing rapidly across AI orchestration frameworks, model-serving infrastructure, and enterprise AI gateways. Security teams should pay particular attention to these platforms because they often provide access to sensitive data, cloud resources, and business-critical AI services.
AI is helping security teams discover serious vulnerabilities faster, but that same acceleration increases pressure on organizations to assess and remediate risks more quickly. As AI adoption grows, enterprises benefit from better security research but must also prepare for a larger and potentially more complex vulnerability landscape.
This report suggests AI is changing both the scale and nature of vulnerability discovery. For IT and security leaders, the challenge is patching more vulnerabilities, as well as identifying which ones pose the highest real-world risk before attackers can exploit them.