Security Leaders Debate Best Allocation of AI, Automation, and Human Review for Vulnerability Management

Over half of 200 senior security leaders at large enterprises indicated that their current software security workflows cannot scale to handle the volume of findings generated by modern development and scanning tools, with AI-generated code review emerging as a top concern for 40 percent of respondents. Organizations are exploring a tiered approach where automation handles routine, low-risk findings through established processes while AI agents tackle complex investigation tasks requiring multi-step reasoning and impact assessment. The challenge reflects a fundamental shift in vulnerability management driven by faster software development cycles and increased use of AI-assisted code generation, leaving security teams struggling to keep pace.
Organizations managing software security face mounting pressure from dual sources: developers now ship code faster using AI assistance, while security scanning tools simultaneously generate exponentially larger findings volumes. The median time to fully resolve critical vulnerabilities currently stretches to 43 days, creating dangerous exposure windows. Most large enterprises lack the human resources to manually review and prioritize every flagged issue, particularly as AI-generated code compounds the backlog of items requiring human assessment and decision-making before remediation can begin.
This challenge could reshape cybersecurity practices across large enterprises, potentially affecting millions of users whose data depends on timely vulnerability fixes. Security teams that cannot effectively triage findings may see exploitable weaknesses persist longer, increasing breach risk. Conversely, organizations adopting tiered automation-to-human workflows could free security professionals to focus on high-judgment decisions rather than routine triage, possibly improving both response speed and security outcomes. The outcome may depend partly on whether enterprises successfully implement AI agents and automation without sacrificing human oversight of critical risk decisions.