{
  "id": 235339,
  "title": "AI struggles to patch vulns without adult supervision",
  "url": "https://urgent.news/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-06T19:04:30.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319"
  },
  "original_language": "en",
  "account": "A recent study conducted by researchers at 1Password's Off-by-1 Labs has revealed concerning findings about the effectiveness of AI-powered security patches. When tested, two frontier models - ChatGPT 5.5 and Claude Opus 4.8 - produced autonomous patches that only correctly fixed vulnerabilities approximately 26% of the time. The remaining 74% of patches either failed to fully resolve the vulnerability or introduced new issues. Keith Hoodlet, the director of security research at 1Password, emphasized the need for human review in the process, stating that across six recently disclosed CVEs, the average success rate for generating a fully resolved patch was a mere 26.0%. Of the AI-generated patches, 20.1% altered application behavior, while 2.3% introduced new security issues. In total, 49.3% of patches failed to fix at least one existing exploit path, and 2.2% both failed to fix the vulnerability and introduced a new exploit path. The researchers coined the acronym FLAWED to describe these automated LLM patches, which stand for Fix-Like Artifacts With Embedded Defects. The study suggests that the cost-effectiveness of AI-generated patches may be misleading, and that human supervision is crucial for ensuring the safety and effectiveness of the patches.",
  "summary": "Left alone, autonomous fixes often fail to fully remediate flaws",
  "key_points": [
    "AI-powered patches correct only 26% of vulnerabilities",
    "Human review needed for safety and effectiveness",
    "FLAWED acronym describes automated LLM patches"
  ],
  "editors_take": "The study's findings underscore the need for human oversight in AI-powered security patching, as automated patches often fail to fully resolve vulnerabilities or introduce new issues, rendering them unreliable without adult supervision.",
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "AI struggles to patch vulns without adult supervision",
        "url": "https://urgent.news/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision-238066",
        "published": "2026-08-06T19:04:30.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}