OpenSSF Finding and Fixing Vulnerabilities Using AI

3.2 Do not wait for access to the best AI models

Do not wait until you have access to the most advanced restricted-access AI models. Instead:

  1. Get started now. Projects typically find many vulnerabilities when they use reasonably good, widely available AI systems, unless they’ve already been using them [Carlini2026] [CSA2026] [Grinstead2026-05] [Stenberg2026-05a]. AI systems now “find lots of new problems no one detected before.” [Stenberg2026-05b]
  2. Apply less-costly models that can find many vulnerabilities at an accessible cost.
    1. “Focusing on Mythos is a distraction - there are plenty of good models, and people who can figure out how to get those models and tools to find things.” [Stenberg2026-05b]
    2. “Frontier models… are the acceleration, not the starting gun” [CSA2026].
    3. If you use an external organization’s services, they will often have more expensive, sophisticated models as well as less expensive, less complex ones. Many open-weight models are available as well.
    4. In short, don’t wait for difficult-to-access and often expensive leading-edge tools for problems that could have been found and fixed more easily. By all means, use advanced models and tools (at least eventually) if you have access to them, but do not wait for them.
  3. Act quickly. “Success comes from getting the basics right, acting quickly, and integrating cyber security into core business strategy” and not from “having the most tools” [FiveEyes2026].
  4. Learn by doing. It takes time to learn and adopt these tools. Practice is the only way to get better. “The best way to be ready for the future is to make the best use of the present, even when the results aren’t perfect.” [Carlini2026]

Cycode noted that independent research from AISLE has already shown that even small open-source models (including a 3.6-billion-parameter model with the right scaffolding) can find many of the same flagship vulnerabilities Mythos showcased. “Vulnerability discovery is commoditizing. The bottleneck is no longer finding bugs. It is deciding which ones to fix first, fast enough to matter.” [Cycode2026]

Different AI models and harnesses have different strengths and weaknesses. In practice, you’ll often want to eventually use multiple ones. The most advanced frontier model “needs to be mounted in the right harness and equipped with the right tools to reach its full potential. And even then, it should just be one of the arrows in your quiver – depending on the task, it may be more sensible to let another model try several times than to let Mythos Preview try once… XBOW maintains a cadre of models, rather than restricting itself to a single one.” [Ziegler2026]

Do use good AI models and systems when available to you. Strong models and systems can produce extraordinary results. However, don’t wait until you gain access to the best possible systems. Many of those systems have restricted access and will delay your getting started. Attackers aren’t waiting.

Quiz

Q1. What does the material recommend about waiting for access to the most advanced, restricted-access AI models?

  1. Wait for frontier-model access, since lesser models can’t find real bugs
  2. Only proceed once you obtain special government-approved model access
  3. Get started now using reasonably-good, widely-available models rather than waiting
  4. Focus first on building your own custom model from scratch, to maximize success
Show answer Answer: C
Quiz

Q1. What does the material say about non-frontier, open-weight models?

  1. They can’t find real vulnerabilities without extensive human guidance
  2. They’re prohibited from being used in vulnerability research entirely
  3. They require far more compute than frontier models to run
  4. They can often find vulnerabilities at an accessible, affordable cost
Show answer Answer: D