The acting US federal chief information security officer and the head of the UK's National Cyber Security Centre (NCSC) say AI is widening the vulnerability backlog, and the path ahead looks "rocky."
At Black Hat in Las Vegas on Wednesday, officials said AI models are finding software flaws faster than defenders can fix them, and they don't see a quick resolution.
"We are discovering vulnerabilities at scale in ways that we never have before; we are piling up the vulnerabilities in need of remediation higher than they've ever been stacked before," a source said at the panel, per E&E News.
A UK official called the near-term outlook "a really, really rocky road," pointing to years of "underinvestment" in cybersecurity as a reason defenders are starting from behind. The UK's National Cyber Security Centre separately published a blog this month, "Preparing for a 'vulnerability patch wave'," signaling that UK officials expect the vulnerability backlog to keep growing.
Advanced models from OpenAI and Anthropic were named as part of the pressure on defenders, while both officials pointed to AI also helping the defense side. CISA's "Patch Smarter, Not Harder" initiative and the agency's separate AI-enabled vulnerability detection pilot show the same agencies trying to close the gap with the same class of tools.
The officials offered no timeline for when the backlog would ease.