30 Jun 2026

AI security's human bottleneck: finding got cheap, fixing didn't (Patch the Planet); runs before jagged-frontier post

AI security's human bottleneck: finding got cheap, fixing didn't (Patch the Planet); runs before jagged-frontier post

The reassuring version of AI in cybersecurity runs roughly like this: the machines find the flaws, the machines write the fixes, and software slowly gets safer on its own.

This is the premise on which GPT-Cyber works. It is half right, but the missing half is the one that matters.

What AI has actually done is make it cheaper and faster to find vulnerabilities. Fixing them has not scaled in the same way. A bug still has to be confirmed, assessed for severity, patched without breaking anything around it, tested, accepted by maintainers, and disclosed with care. Almost all of that still runs through human hands.

The bottleneck has not gone away; it has simply shifted position in the workflow. It has moved from finding to fixing, and from machines back to people.

OpenAI's recent Patch the Planet effort, built with Trail of Bits, shows its shape. In the first week, Trail of Bits reported hundreds of discovered bugs, 64 pull requests and 51 issues across 19 open-source projects. Dozens of patches were already merged.

That sounds like the machine-speed future arriving, but why did it work? By Trail of Bits' own account, only about half the effort went into finding bugs at all; the rest was the human work around the models. Reviewing findings and removing false positives. Turning outputs into patches a maintainer could safely accept.

Anyone running a business with open-source software should pay attention.

The people doing the fixing are often volunteers or small maintainer groups, and they are already stretched. AI has just handed them a firehose of fresh reports to sort through, the real mixed in with the merely plausible and a healthy dose of hallucinations.

So a lopsided balance has already tilted further. Discovery scales with compute. Validation, judgement and repair scale with scarce human attention, and that attention is spread thin across the libraries your stack might depend on.

Your exposure, then, is less about how clever your AI security tools are than about whether the people maintaining the code you depend on can keep pace. Most businesses could not even name them.

AI has made it cheap to find what is broken. It has done far less to find the people who will fix it.

Originally published on LinkedIn

Want to apply this to your business?

If this sparked a useful question, let’s talk about where AI, automation, or product strategy can create practical leverage in your organisation.

Start the conversation