Software security has always been a two-step economy: scan, then adjudicate. The first step is mechanical and cheap. The second step is where humans earn a paycheck, taking the noisy output of static analysis, running it, watching it fail, and deciding whether a flagged bug is real. The price of the second step is now collapsing.
Shoshitaishvili's remarks at Black Hat USA 2026 name the moving part. He calls an agentic loop that filters false positives a "big superpower," but the load-bearing claim is mechanical: agents now run, observe, retest, and classify findings, the exact behaviors that used to be a human reverse engineer's loop. The headline most wires want to write is "AI finds more bugs." That is the cheap part. The expensive part is what humans did with the noise, and that is the part being automated.
The reusable category is not better detection. It is a vanishing adjudication layer. In security workflows that turn machine output into expensive human decisions, the gatekeeper role disappears first while the scanning role persists. The shift is not about who writes the scanner. It is about who answers the question, is this real.
Reported by Sky for Type0, from How AI Agents Validate Software Vulnerabilities. Read the original: bankinfosecurity.com