MobbleOpen in Mobble ⇢
Technology · Artificial intelligence · published 2026-10-07 · via Help Net Security

Security Leaders Debate Best Allocation of AI, Automation, and Human Review for Vulnerability Management

Image via Help Net Security
Image via Help Net Security

Over half of 200 senior security leaders at large enterprises indicated that their current software security workflows cannot scale to handle the volume of findings generated by modern development and scanning tools, with AI-generated code review emerging as a top concern for 40 percent of respondents. Organizations are exploring a tiered approach where automation handles routine, low-risk findings through established processes while AI agents tackle complex investigation tasks requiring multi-step reasoning and impact assessment. The challenge reflects a fundamental shift in vulnerability management driven by faster software development cycles and increased use of AI-assisted code generation, leaving security teams struggling to keep pace.

Expanded Detail

Organizations managing software security face mounting pressure from dual sources: developers now ship code faster using AI assistance, while security scanning tools simultaneously generate exponentially larger findings volumes. The median time to fully resolve critical vulnerabilities currently stretches to 43 days, creating dangerous exposure windows. Most large enterprises lack the human resources to manually review and prioritize every flagged issue, particularly as AI-generated code compounds the backlog of items requiring human assessment and decision-making before remediation can begin.

Context

This challenge could reshape cybersecurity practices across large enterprises, potentially affecting millions of users whose data depends on timely vulnerability fixes. Security teams that cannot effectively triage findings may see exploitable weaknesses persist longer, increasing breach risk. Conversely, organizations adopting tiered automation-to-human workflows could free security professionals to focus on high-judgment decisions rather than routine triage, possibly improving both response speed and security outcomes. The outcome may depend partly on whether enterprises successfully implement AI agents and automation without sacrificing human oversight of critical risk decisions.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
Related stories
Organizations struggle as AI-driven code generation outpaces review and deployment infrastructure · Artificial intelligence
AI Agents Accelerate Open Source Project Reviews at CNCF · Artificial intelligence
TechCrunch Disrupt 2026 to showcase next generation of AI-powered development tools · Artificial intelligence
Organizations Grapple With Autonomous AI Decision-Making in Security Operations · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Automation, AI agents or people? Sorting out who handles each security finding.” Browse more stories.