OpenSSF Finding and Fixing Vulnerabilities Using AI

3.6 How to apply processes for using AI to find and fix vulnerabilities

So while AI systems can, with a good model, sometimes find and fix some vulnerabilities, we usually want to be more thorough. How can we apply those processes, though?

These added processes for finding and fixing vulnerabilities can be human-guided, automation-guided, or a mix:

Unsurprisingly, many different organizations and projects have developed processes to improve finding and fixing vulnerabilities using AI. As noted by Cycode, “AI-driven vulnerability discovery is no longer a single-vendor story. It is an industry capability, and it has arrived faster than most security programs are prepared for.” [Cycode2026]

Here are a few examples of processes people have used (beyond the list from [Bourzikas2026] and [Yan2026] we showed earlier):

Most of these systems can be used with three types of scanning actions: