AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
Microsoft's release of over 970 patches in a single week recently overwhelmed many security teams, but Gartner research vice president Craig Lawson believes this crunch may be temporary. Speaking at Gartner's IT Symposium in Australia, Lawson argued that AI-powered bug-hunting tools are uncovering flaws in established codebases at a scale never seen before, potentially clearing out years of accumulated technical debt in software that has long been considered stable and secure.
Lawson pointed to software vendors, including security companies, increasingly using AI tools to find vulnerabilities in their own products before release. He suggested this could mean fewer opportunities for attackers to exploit undiscovered zero-day flaws in future software versions. While 2026 has seen a record number of vulnerabilities reported, Lawson believes this reflects a thorough cleanup process rather than software becoming less secure, and that 2027 could bring a drop in the severity of flaws being found.
Beyond bug detection, Lawson suggested AI could also transform how defenders operate day to day, potentially enabling businesses to run red-team style security testing far more frequently and affordably than the occasional, costly exercises many rely on today. He also suggested AI tools could help analysts draft fixes or virtual patches more quickly when issues are identified.