
Speed has always mattered in cybersecurity. But today, the difference between identifying a vulnerability in a matter of hours and discovering it days or weeks later can have significant consequences.
The pace of vulnerability discovery is accelerating rapidly. By mid-September 2026, 66,401 software vulnerabilities had been recorded globally, compared with 33,512 during the same period a year earlier. For context, around 25,000 vulnerabilities were recorded throughout 2022, the year ChatGPT was introduced.
The numbers point to a broader shift in cybersecurity. Artificial intelligence is not necessarily creating all these vulnerabilities. Instead, it is increasingly helping security researchers and organizations find weaknesses that may have previously remained undiscovered.
For security teams, however, faster discovery creates another question: what happens when vulnerabilities are found faster than organizations can assess and remediate them?
At first glance, finding more vulnerabilities should be a positive development. The earlier a vulnerability is identified, the sooner it can potentially be addressed.
The challenge is scale.
Security and IT teams have limited time and resources to analyze findings, determine their severity, prioritize remediation and coordinate fixes across increasingly complex environments. As the volume of findings increases, simply identifying vulnerabilities is no longer the only challenge.
This shift will be one of the topics discussed at Automation Summit, taking place on October 15 and 16 in Split, Croatia.
The third edition of the regional conference will bring together professionals working with AI and automation across industries, with discussions focused on how organizations can move from experimentation to practical implementation.
The cybersecurity perspective is particularly relevant because automation can help address one of the biggest constraints facing security teams: the amount of repetitive work required to turn a security finding into an actionable response.
As Francesca Curzi, Vice President – HCL Automation Orchestration, DevOps and Mainframe Sales Head at HCLSoftware AI & Automation, points out, the growing volume of vulnerabilities creates a capacity problem as much as a detection problem. The ability to automatically identify issues is developing faster than the ability of organizations to manually analyze, prioritize and remediate them.
That is where automation becomes more than an additional security tool. It becomes part of the infrastructure needed to coordinate detection, prioritization and remediation across increasingly complex environments.
For Robert Preskar, Security & Compliance Line of Business Manager at ASEE, the rapid growth in vulnerability discoveries and security patches is a natural consequence of AI becoming increasingly embedded in software development.
“Generative AI is an extremely powerful tool that significantly accelerates both sides of the equation: finding vulnerabilities and fixing them.”
The important point, however, is that AI is not operating exclusively on one side of the security equation.
The same technologies that can help security teams identify vulnerabilities can also help developers analyze and address them. As AI becomes more deeply integrated into development workflows, security testing and penetration testing, the overall quality of software may improve as well.
Preskar expects the current acceleration to eventually stabilize as organizations learn to use AI throughout the software lifecycle.
But the transition itself creates a period of uncertainty.
Not every organization will adopt new technologies at the same pace, and the gap between organizations that can adapt quickly and those that cannot may become increasingly important.
Preskar sees one of the most significant risks in AI-powered attacks that target people and their behavior, as well as infrastructure and products that fail to keep pace with technological change.
This is an important reminder that investing in new security technologies is only one part of the equation. Employee awareness and the ability to recognize increasingly convincing fraud attempts and other forms of social engineering remain critical.
AI may automate technology faster than it can automate human judgment, responsibility and behavior.
The security conversation becomes even more complex as organizations move beyond traditional generative AI tools toward AI agents capable of interacting with business systems and carrying out tasks autonomously.
That introduces a different category of security questions.
An AI agent may have access to company data, communicate with users, trigger workflows or initiate actions in business systems. As a result, security can no longer focus only on whether an AI system produces an accurate answer.
It also needs to address what the system is allowed to access and what it is allowed to do.
As Siniša Behin, co-founder of Datum, explains, this makes AI-agent security a business concern as much as a technical one. Identity and access management, permissions, monitoring and clearly defined boundaries become essential when autonomous systems are given access to sensitive business environments.
The principle is straightforward: the more autonomy an organization gives an AI agent, the more precisely it needs to define and monitor that agent's boundaries.
This is particularly important when AI agents operate on company infrastructure or interact with sensitive data.
These developments are making it increasingly difficult to treat cybersecurity as a standalone IT discipline.
Consider an AI agent with access to a CRM system, financial information, internal databases or operational workflows. Deciding what that agent can access, which actions it can perform and when human approval is required is no longer purely a technical decision.
It affects data protection, business continuity, compliance, operational risk and customer trust.
That is why conversations around AI and automation increasingly need to involve security, IT, business and leadership teams together.
At ASEE, we see this intersection as particularly important as organizations adopt AI across their operations. Automation can help security teams handle increasing volumes of data and findings, but it also introduces new systems, connections and permissions that need to be secured from the outset.
The goal is not simply to automate more.
It is to build systems where automation, security and human oversight work together.
The question is therefore no longer whether AI can find vulnerabilities that humans might miss. It already can.
The bigger challenge is what organizations do with those findings once they appear.
Can they distinguish critical issues from lower-risk findings? Is prioritization effective? Can they automate repetitive remediation processes without losing human oversight? And can their security controls keep pace as AI systems themselves become more autonomous?
These questions will be part of the broader conversation at the third edition of Automation Summit, where AI and automation will be explored through practical implementations across industries including finance, healthcare, telecommunications, logistics, retail and energy.
For cybersecurity teams, the opportunity is significant. AI can accelerate detection, analysis and remediation. Automation can help organizations manage the resulting scale. But neither eliminates the need for human judgment.
Instead, the organizations best positioned for this next phase will be those that understand where AI can take over repetitive work, where automation can improve response times, and where people still need to remain firmly in control.
Automation Summit takes place on October 15 and 16. Join us for two days of conversations and real-world perspectives on AI and automation. See you in Split! Learn more about Automation Summit or get your ticket via Entrio.
This article is adapted from the original published on jutarnji.hr.