For two decades the security industry raced to find vulnerabilities faster. That race is over, and the winning side is the machine. What it leaves behind is a backlog that humans alone cannot close. The evidence suggests the bottleneck has moved from discovery to remediation, and every workflow built around the old shape is now misaligned.
Read any vendor's disclosure numbers and the asymmetry is the same. When Google surfaced 1,072 Chrome security bugs in sixty days, that was not a finding triumph; it was a remediation alarm. Apple's June 2026 move to throttle researcher submissions is the tell that vendors are now managing the inflow, not the fix. Microsoft's July 2026 Patch Tuesday, with 570 fixes shipped, and the arXiv analysis of agent-generated patches across more than twenty thousand SWE-bench issues, point the same direction. AI did not break security. It exposed where the work actually lives.
The evidence suggests the repeatable mechanism is this: as long as machine surfacing outpaces human closing, the binding constraint is triage and patching capacity, not detection. The fix is exploitability-first ranking over raw CVE scores, automation on the closing side, and explicit budget for the back-of-house. The firms that win the next decade will look like software factories, not research teams.
The old instinct was to find more bugs. The new bottleneck decides who can close them.