Some organizations and projects want to simply ignore AI, refuse to use it, or refuse to accept any contributions that use AI. If the goal of the project is solely to demonstrate what humans can do without AI, that’s fine.
However, if the goal of the project is to help people solve a real-world problem, refusing to consider all AI-generated work is extremely harmful to project users. As Michael Catanzaro notes, “banning good vulnerability reports solely because some portion of the report was generated by AI is unacceptable. AI-assisted vulnerability reports are the new industry standard… Prohibiting issue reports reduces the quality and safety of your software, punishing your users.” [Catanzaro2026]
In addition, defenders who ignore AI are at a fundamental speed disadvantage. “Defenders… that do not adopt AI coding agents cannot match the speed or scale of AI-augmented threats, regardless of their technical skill.” [CSA2026] “Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find.” [Stenberg2026-05a]
The CSA recommends that organizations require AI agent adoption by their employees: “Formalize AI agent usage (mostly in the form of coding agents) as part of all security functions, with mandatory security controls and oversight in place. … Optional adoption programs have not been shown to overcome cultural barriers, while adoption is a limiting factor….” [CSA2026]
Note that this doesn’t mean that all or any code must be AI-generated. AI-generated code can in some cases be terrible for security. However, that’s different from trying to entirely ignore AI.
Trying to withstand AI-enabled attackers, while refusing to use AI to find vulnerabilities and ignoring reports from those who use AI, can only end one way: compromise.
Attackers prefer developers who ignore vulnerability reports or who fail to fix vulnerabilities, since that makes their tasks easier. Attackers are already using AI to create multi-step complex attacks that reliably defeat software systems whose developers were not prepared for AI-assisted attacks. The more defenders who won’t use AI to find vulnerabilities, and who ignore vulnerabilities found with AI, the more systems that can be subverted and the more people who will be harmed.
You need to use AI to help find vulnerabilities, and then fix those vulnerabilities, if the software must be secure. Do not bring a knife to a gunfight.

Q1. What’s a risk if a project bans all AI-assisted vulnerability reports?