O que aconteceu
Help Net Security reports that risk managers, auditors and senior executives at 316 companies ranked AI discovery of cyber vulnerabilities as the highest-impact threat in Gartner’s latest quarterly survey. Respondents said the risk could produce tangible effects in less than two years, although the survey measured perceptions rather than demonstrated attacks or defenses.
Help Net Security reports that Gartner asked risk managers, auditors and senior executives at 316 companies to rank 20 emerging threats that their organizations had not yet experienced. In the survey conducted during April and May, AI discovery of cyber vulnerabilities ranked first for potential impact. Help Net Security says this was a sharp change from the same quarterly survey three months earlier, when information-integrity risk ranked first and AI vulnerability discovery was outside the top five. The source does not provide the full questionnaire, the identities of participating companies or an independently published Gartner methodology in the supplied material.
Help Net Security reports that respondents assigned the vulnerability-discovery risk an average time-frame score of 1.92. The outlet explains that the scale runs from 1, meaning tangible impact in less than a year, to 2, meaning impact in one to two years. Seventy-six percent of respondents placed the risk in their top 10. The risk ranked first in each of the four regions listed by the outlet: 78% in Europe, 78% in Asia-Pacific, 75% in the Americas, and 70% in the Middle East and Africa. Banking, financial services and insurance respondents selected it at 78%, compared with 74% among other respondents.
The source attributes the shift to two developments. Help Net Security reports that AI systems can scan for previously unknown flaws at a volume that traditional patching teams cannot absorb, while the time between finding a flaw and producing working attack code has become much shorter. It also reports that AI models have improved at generating functional exploits and names Anthropic’s Project Glasswing and OpenAI’s Daybreak as defensive efforts intended to identify and patch exploitable code. Those claims are attributed to Help Net Security’s report; the supplied source does not independently demonstrate the models’ real-world success rates, the number of vulnerabilities involved or whether any particular incident resulted from this capability.
The survey produced a notable contrast in preparedness. Help Net Security reports that AI vulnerability discovery ranked first not only for impact but also for respondents’ self-assessed preparedness, while ranking third for proximity. The outlet says preparedness was measured on a five-point scale, with the highest mark indicating that the risk was actively discussed and that steps were in place. The report also makes clear that the survey did not test those steps against the capability that pushed the risk to the top of the impact ranking. This means the preparedness result describes confidence and reported planning, not verified resilience.
Leia a fonte primária: helpnetsecurity.com ↗
Por que isso importa
The finding reflects concern that AI may increase both the volume of vulnerabilities discovered and the speed at which attackers can turn them into working exploits. That could leave organizations with remediation backlogs that grow faster than security teams can clear them, particularly where third-party systems and AI-integrated infrastructure are difficult to inspect.
The practical concern is a widening gap between vulnerability discovery and remediation. Help Net Security reports that defenders could inherit a backlog of unpatched critical vulnerabilities that grows faster than it can be cleared. If AI-assisted scanning expands the number of findings while AI-assisted exploitation lowers the cost of attacking them, organizations may face less time to assess, prioritize and fix flaws. The source does not establish that this pattern is already occurring at a measured industry-wide rate, but it presents the prospect as the central reason respondents ranked the risk so highly.
The risk could extend beyond conventional patch-management workloads. Help Net Security reports that AI integration has made some systems harder to see into and connects faster vulnerability discovery with third-party exposure, business-continuity risk and legal exposure. In practical terms, an organization may need to determine not only whether its own code is vulnerable but also whether suppliers, hosted services and integrated AI systems have been affected. The supplied article does not identify a specific breach, victim, exploitable product or confirmed incident, so these consequences should be treated as risk scenarios rather than documented outcomes.
The source quotes Kevin Mercado, a senior principal analyst in Gartner’s Risk & Audit Practice, as saying that AI is making vulnerability discovery more efficient and accessible, while traditional risk-management approaches may struggle to keep pace. He warns, according to Help Net Security, that without corresponding improvements in governance, security operations and remediation, AI-driven discovery could outpace organizational defenses and raise the likelihood of serious cyber incidents and operational disruption. This is an attributed expert assessment, not an independently verified forecast.
Help Net Security reports that AI vulnerability discovery did not appear among the five risks respondents associated with the greatest business upside. Those five were AI-driven competitive displacement, agentic AI, AI-driven skill erosion, AI intellectual-property control and U.S. financial deregulation. The contrast matters because it suggests that respondents viewed vulnerability discovery primarily as a defensive burden rather than as a capability that creates direct business value. The supplied material does not show how respondents defined those categories or whether they evaluated benefits and harms using comparable measures.
O que assistir a seguir
The key test is whether organizations’ self-reported preparedness translates into faster discovery, validation and remediation. Help Net Security reports that the survey did not test respondents’ controls against AI-enabled capabilities, leaving open questions about actual readiness, the quality of the underlying data and how often AI-generated exploits work in real environments.
The first indicator will be whether organizations can shorten the time from finding a vulnerability to validating, prioritizing and fixing it. Help Net Security reports that the survey points toward faster and more automated remediation, along with a reassessment of cyber-risk impact, risk appetite for continuous exposure and the maximum acceptable period for leaving a vulnerability unpatched. These are recommendations reported by the outlet, not evidence that a particular organization has adopted them.
Vendor and supply-chain verification will be another pressure point. Help Net Security reports that the survey recommendations include stronger security validation from vendors, particularly around whether systems may already be compromised. That would require organizations to obtain more timely and credible evidence about dependencies they do not directly operate. The source does not specify what validation standards, audit methods or contractual requirements Gartner recommends, so the effectiveness of this approach remains unknown.
A second question is whether AI-generated exploit code works reliably outside controlled testing. The article reports that the exploit-writing step has become nearly frictionless and that AI models have improved at producing working exploits, but it supplies no benchmark, case study, incident record or independently replicated test. Readers should therefore distinguish between reported capability improvements and demonstrated operational impact. The survey measures what respondents expect and fear, not how often attackers have successfully used such systems.
Finally, the apparent preparedness paradox deserves scrutiny. Respondents ranked the risk first for impact and first for preparedness, yet Help Net Security says the survey did not test their controls against AI-enabled vulnerability discovery or exploitation. Future evidence should include observed remediation times, false-positive rates, third-party exposure, successful exploit attempts and whether security teams can maintain coverage as discovery volume rises. Until such measurements are available, the Gartner result is best understood as a significant signal of executive concern rather than proof that AI-driven vulnerability discovery has already produced a broad wave of incidents.


