{
  "id": 9306342,
  "title": "AI floods security teams with findings. The advantage is in what happens next",
  "url": "https://urgent.news/2026/09/23/ai-floods-security-teams-with-findings-the-advantage-is-in-what",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-23T09:28:21.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/ai-floods-security-teams-with-findings-the-advantage-is-in-what-happens-next"
  },
  "original_language": "en",
  "account": "In the past year, security teams utilizing our platform have managed to trim the time required to address critical vulnerabilities by approximately 50%. Concurrently, the backlog of unaddressed critical vulnerabilities has surged nearly 29 times. These statistics encapsulate the predicament that security leaders will soon confront. Artificial intelligence (AI) now possesses the capability to assess software at scales previously unattainable through manual testing. By scrutinizing code and perusing thousands of assets for recognizable vulnerability patterns, AI surfaces exposures more swiftly and earlier than human teams could. For businesses striving to keep pace with an ever-expanding attack surface, this augmented reach is genuinely beneficial. However, it also underscores a previously underestimated weakness: many organizations lack the capacity to validate, prioritize, and remediate findings at a rate commensurate with the speed at which AI can generate them. This disparity constitutes the primary challenge Continuous Threat Exposure Management (CTEM) aims to resolve. CTEM furnishes organizations with a continuous process for comprehending their attack surface, identifying vulnerabilities, substantiating their exploitability, and directing remediation efforts towards the exposures that pose the most significant business risk. While AI excels in the discovery phase, its impact on remediation and engineering capacity is limited. Consequently, the gap between discovery and remediation is widening. Security professionals have conventionally perceived discovery as a capacity issue: scrutinize more assets, cover a broader codebase, and detect weaknesses at an earlier stage. AI provides a definitive answer to this question. However, the discovery of a potential vulnerability merely marks the beginning of the process; it is merely the starting point. Each finding still necessitates confirmation of exploitability and assessment of severity within the specific context where the technology operates. Subsequently, it must reach the appropriate engineering team, receive priority over existing tasks, undergo rectification, and be retested to validate the fix. AI accelerates the initial step but barely touches the subsequent stages. This is why the two figures mentioned earlier can both be accurate. An increasing number of findings may indicate enhanced coverage, while more rapid repairs might coexist with an expanding backlog when discovery accelerates faster than remediation, and engineering capacity shifts in the opposite direction. Neither figure holds significance in isolation. The only perspective that truly matters spans the entire journey, from initial detection to substantiated resolution. Validation presents the critical bottleneck. Although AI has reduced the cost of generating persuasive security reports, some of these reports either highlight genuine weaknesses or duplicate known findings, misinterpret the target, or describe theoretical issues with minimal practical risk. Regardless, each report must undergo investigation. While AI has expedited the generation of convincing security reports, a report that takes mere seconds to produce can consume hours of an experienced analyst's time before it can be dismissed with confidence. At enterprise scale, this is how urgent findings become buried. A well-substantiated vulnerability with a credible attack path competes with hundreds of submissions that sound plausible but ultimately lead to nowhere. Security teams must distinguish the genuine AI-generated insights from the AI-generated noise, determine which real findings hold the most significance, and accomplish this feat with engineering capacity that has not grown in tandem with the volume of submissions. Continuous Threat Exposure Management (CTEM) emerges as the solution to this predicament. CTEM equips organizations with a continuous methodology for understanding their attack surface, pinpointing weaknesses, validating their exploitability, and directing remediation efforts towards the exposures that carry the most significant business risk. While AI excels in the discovery phase, its impact on remediation and engineering capacity is limited. As a result, the disparity between discovery and remediation is expanding. Security professionals have traditionally viewed discovery as a capacity issue: scrutinize more assets, cover a broader codebase, and detect weaknesses at an earlier stage. AI provides a definitive answer to this conundrum. However, the discovery of a potential vulnerability is merely the beginning of the process; it is merely the starting point. Each finding still requires confirmation of exploitability and assessment of severity within the specific context where the technology operates. Subsequently, it must reach the appropriate engineering team, receive priority over existing tasks, undergo rectification, and be retested to validate the fix. AI accelerates the initial step but barely touches the subsequent stages. This is why the two figures mentioned earlier can both be accurate. An escalating number of findings may signify improved coverage, while more rapid repairs might coexist with an expanding backlog when discovery accelerates faster than remediation, and engineering capacity moves in the opposite direction. Neither figure holds significance in isolation. The only perspective that truly matters spans the entire journey, from initial detection to substantiated resolution. Validation emerges as the critical bottleneck. Despite AI's ability to generate convincing security reports, some of these reports either highlight genuine weaknesses or duplicate known findings, misinterpret the target, or describe theoretical issues with minimal practical risk. Regardless, each report must undergo investigation. While AI has expedited the generation of convincing security reports, a report that takes mere seconds to produce can consume hours of an experienced analyst's time before it can be dismissed with confidence. At enterprise scale, this is how urgent findings become buried. A well-substantiated vulnerability with a credible attack path competes with hundreds of submissions that sound plausible but ultimately lead to nowhere. Security teams must distinguish the genuine AI-generated insights from the AI-generated noise, determine which real findings hold the most significance, and accomplish this feat with engineering capacity that has not grown in tandem with the volume of submissions.",
  "summary": "AI is accelerating vulnerability discovery, but organizations must strengthen validation, prioritization and remediation to reduce risk.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}