OpenSSF Finding and Fixing Vulnerabilities Using AI

3.1 Do not ignore AI

Some organizations and projects want to simply ignore AI, refuse to use it, or refuse to accept any contributions that use AI. If the goal of the project is solely to demonstrate what humans can do without AI, that’s fine.

However, if the goal of the project is to help people solve a real-world problem, refusing to consider all AI-generated work is extremely harmful to project users. As Michael Catanzaro notes, “banning good vulnerability reports solely because some portion of the report was generated by AI is unacceptable. AI-assisted vulnerability reports are the new industry standard… Prohibiting issue reports reduces the quality and safety of your software, punishing your users.” [Catanzaro2026]

In addition, defenders who ignore AI are at a fundamental speed disadvantage. “Defenders… that do not adopt AI coding agents cannot match the speed or scale of AI-augmented threats, regardless of their technical skill.” [CSA2026] “Not using AI code analyzers in your project means that you leave adversaries and attackers time and opportunity to find and exploit the flaws you don’t find.” [Stenberg2026-05a]

The CSA recommends that organizations require AI agent adoption by their employees: “Formalize AI agent usage (mostly in the form of coding agents) as part of all security functions, with mandatory security controls and oversight in place. … Optional adoption programs have not been shown to overcome cultural barriers, while adoption is a limiting factor….” [CSA2026]

Note that this doesn’t mean that all or any code must be AI-generated. AI-generated code can in some cases be terrible for security. However, that’s different from trying to entirely ignore AI.

Trying to withstand AI-enabled attackers, while refusing to use AI to find vulnerabilities and ignoring reports from those who use AI, can only end one way: compromise.

Attackers prefer developers who ignore vulnerability reports or who fail to fix vulnerabilities, since that makes their tasks easier. Attackers are already using AI to create multi-step complex attacks that reliably defeat software systems whose developers were not prepared for AI-assisted attacks. The more defenders who won’t use AI to find vulnerabilities, and who ignore vulnerabilities found with AI, the more systems that can be subverted and the more people who will be harmed.

You need to use AI to help find vulnerabilities, and then fix those vulnerabilities, if the software must be secure. Do not bring a knife to a gunfight.

A robot tries to warn a human about a fire, but the human is ignoring the robot

Quiz

Q1. What’s a risk if a project bans all AI-assisted vulnerability reports?

  1. It has little effect, since attackers rarely rely on AI themselves
  2. It reduces the software’s overall quality and safety by rejecting valid reports
  3. It automatically violates the terms of the project’s open source license
  4. It disqualifies the project from ever receiving CVE identifiers
Show answer Answer: B