OpenSSF Finding and Fixing Vulnerabilities Using AI

1.5 What hasn’t changed

Despite these large increases in the speed of finding and exploiting vulnerabilities, the fundamental principles of developing secure software have not changed. Those fundamental principles are still the best defense.

“AI does not change the fundamentals of… security. Least privilege, minimal attack surfaces, coordinated vulnerability disclosure, and proactive security engineering still win. What AI changes is the velocity of attacks, of reports, of fixes, and of the expectations placed on maintainers and security engineers alike. The communities and projects that learn to work with these tools intentionally will be better positioned than those that ignore them or are overwhelmed by them.” [Aniszczyk2026]

In short, the “normal” security tasks are still important with AI [Oshungboye]. AI generally isn’t finding entirely new kinds of vulnerabilities in software [Holley2026]; it is finding the same old kinds of vulnerabilities caused by sloppy practices and failure to apply best practices. By applying already-known best practices, and using AI defensively to speed up their implementation, it’s possible to address the problem of AI-amplified attacks. The following material details how to adopt those principles using AI.

Woman directs robot to build a wall while applying security principles