In the longer term, there is great news for defenders. As Bobby Holley of Mozilla put it, “Defenders finally have a chance to win, decisively…. the defects are finite, and we are entering a world where we can finally find them all” [Holley2026].
Holley explains, “security to date has been offensively-dominant: the attack surface isn’t infinite, but it’s large enough to be difficult to defend comprehensively with the tools we’ve had available. This gives attackers an asymmetric advantage, since they only need to find one chink in the armor…. So far we’ve found no category or complexity of vulnerability that humans can find that [Mythos Preview] can’t. This can feel terrifying in the immediate term, but it’s ultimately great news for defenders. A gap between machine-discoverable and human-discoverable bugs favors the attacker, who can concentrate many months of costly human effort to find a single bug. Closing this gap erodes the attacker’s long-term advantage by making all discoveries cheap” [Holley2026].
There’s strong evidence that if a project works hard to find and fix vulnerabilities, it becomes increasingly difficult to find any more, even with AI. For example, the curl project is well-known for working hard to prevent security vulnerabilities. Even the best AI models, when focused on it, have tended to find few vulnerabilities in it [LowLevel2026] [Stenberg2026-05a]. This is not magic; it’s the result of prior efforts to make it secure. Other projects can do the same. Once AI systems are aggressively used to find vulnerabilities, and those are fixed, there’s good reason to believe the resulting system tends to be extremely hard to attack. Since actual software is finite, “there’s a finite number [of vulnerabilities] in a program; once fixed, attackers can’t exploit vulnerabilities that don’t exist.” [Wheeler2026]
Of course, this doesn’t make this easy or pleasant to go through. “You may need to [briefly] reprioritize everything else to bring relentless and single-minded focus to the task” [Holley2026]. Still, there’s reason to believe that once you do this, the resulting software will be far more secure than it’s ever been.
