As we noted earlier, in most cases you should repeatedly apply AI systems to find and fix vulnerabilities.
Most AI systems are non-deterministic; re-running the same AI system with the same inputs can discover new vulnerabilities, especially in the first few iterations. In addition, AI systems will continue to improve, and new capabilities may find new problems.
So you need to repeatedly apply AI systems, especially improved ones, to find vulnerabilities that were previously missed by other passes. As vulnerabilities are found, search for similar patterns elsewhere, and ensure you really did fix the problem systematically.
The good news is that improved hardening and fixing vulnerabilities will eventually eliminate all “easy vulnerabilities” and make the system increasingly difficult to attack. Software is finite, and so are defects. Take heart: as it gets harder for software developers to find vulnerabilities, it also gets harder for attackers to find them.
In practice, software changes over time. Deterministic checks, including those created from earlier findings, should run on every change. An AI system should also analyze each proposed change (pull request or merge request) toidentify vulnerabilities before a change is accepted.

Q1. Why does this material recommend repeatedly rerunning AI systems against the same codebase to look for vulnerabilities, rather than treating a single pass as sufficient?