AI Found Thousands of Bugs, but Patching Was Always the Real Bottleneck
In a caustic personal essay, security engineer Jan Schaumann argues that the industry’s rush to embed AI into vulnerability research has been a costly misfire. Anthropic and OpenAI, he says, competed to hype how ‘dangerous’ their models were, drawing security teams into codenamed collaborations and open letters. Organizations then poured millions of engineering hours into building AI-driven discovery pipelines and shoehorning the resulting findings into their vulnerability-management workflows. The payoff: thousands of new bugs surfaced, only a fraction reported upstream to open-source maintainers, and, in his assessment, no meaningful improvement in actual security.
His central point is that discovery was never the hard part. The persistent bottleneck is remediation — maintaining accurate asset inventories, automating OS and application patching, forcing reboots so updates take effect, and enumerating attack surface across on-prem and cloud. Redirecting a few dozen senior engineers toward those unglamorous fundamentals for six months, he contends, would have bought far more real safety than any model-generated bug list. He also warns of a compounding de-skilling loop: AI finds the flaw, AI writes the patch, AI ‘reviews’ the pull request, and the humans nominally in the loop become rubber stamps who no longer understand their own systems — a serious problem given that debugging opaque, distributed code is far harder than writing it.
The piece widens into a broader indictment of the AI industry: intellectual-property exploitation, concentration of power in a handful of US firms, media that uncritically adopts anthropomorphic framing, and the heavy environmental toll of data centers built as regulators wave through exemptions. Schaumann is especially scornful of companies that publicly beg for regulation over existential-risk fears while continuing to build the very products they claim are dangerous — noting that no law prevents them from simply stopping. The overall tone is one of burnout and refusal: a practitioner declaring he won’t ‘set ethics aside’ and wants off the hype train entirely.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.