Nikesh Arora's All-In appearance is a board-level signal: AI can make buried software risk visible faster than most organizations can patch it.

Arora said AI found vulnerabilities that would normally have taken five to seven years to find.
The broader lesson is that vulnerability discovery is shifting from scarce expert labor to model-accelerated scanning, triage, and exploit-path analysis.
Palo Alto Networks said its May 2026 advisory was the first time the majority of findings came from frontier AI models scanning its code.
products across all three platforms.
covered in May Patch Wednesday.
issues represented in the advisory.
typical monthly volume, according to Palo Alto Networks.
Companies used to rely on the fact that deep code review takes time. That assumption is weakening. Once discovery accelerates, slow remediation becomes the visible failure.
AI can surface hidden defects across code that was never reviewed at modern speed or scale.
Security value depends on triage, ownership, testing, rollout, customer communication, and validation.
Security teams still judge impact, prioritize exposure, coordinate patching, and own outcomes.
A better scanner can reveal more work than the organization is ready to fix. Leadership has to create a system for prioritizing and proving risk reduction.
The winning pattern is not a one-time model run. It is a recurring find, triage, patch, verify, and report loop.
Code, SaaS, customer-facing apps, dependencies, cloud exposure, and AI infrastructure.
Rank by reachability, exploit path, customer impact, privilege, and compensating controls.
Assign product, engineering, security, DevOps, legal, comms, and customer success owners.
Rescan after fixes, test regression, and validate that reachable risk actually went down.
Use segmentation, WAF, endpoint controls, virtual patching, monitoring, and response automation.
Show surface area, risk trend, time-to-fix, residual exposure, and investment constraints.
Boards and executives should ask for proof that model-speed discovery is being converted into customer-risk reduction.
| Question | Weak answer | Stronger answer |
|---|---|---|
| What was scanned? | One repo or one app family. | A named inventory of code, applications, dependencies, exposure, and cloud surfaces. |
| What matters most? | Severity labels only. | Reachability, exploit path, customer impact, privilege, and compensating controls. |
| Who owns fixes? | Security creates tickets. | Product, engineering, DevOps, and security share remediation lanes with dates. |
| How do we prove progress? | Counts of closed issues. | Validated fixes, residual risk, time-to-fix, and customer-facing exposure trend. |
The new security question is not whether AI can find flaws. It is whether the enterprise can absorb model-speed discovery without turning it into unmanaged operational risk.
© 2026 Chander Dhall Methodworks, LLC. All rights reserved.