Security firm VulnCheck reports that only 1.3 percent of AI-discovered software vulnerabilities were confirmed exploited in the first half of 2026, nearly matching exploitation rates for vulnerabilities found by traditional methods. Researcher Patrick Garrity tracked 1,061 AI-assisted vulnerabilities, of which fourteen were exploited. Anthropic’s Project Glasswing yielded over 23,000 findings, but just 126 became published entries and only one has been used in an attack. Although exploitation rates remain low, attacks occur sooner after disclosure: the median time dropped from 120 to 80 days, with about 23 percent exploited on or before disclosure, increasing urgency for faster defensive responses.
This update represents a notable development in the Ai sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.