← Reports
Slides
Read Full Report
01/00·Title
AI Security

AI just changed the vulnerability clock.

Five to seven years of discovery pressure in six weeks.

Nikesh Arora's All-In appearance is a board-level signal: AI can make buried software risk visible faster than most organizations can patch it.

Read Full Report →
Chander Dhall
Chander DhallBuilder • Leader • Speaker
Nikesh Arora quote
6weeks

Arora said AI found vulnerabilities that would normally have taken five to seven years to find.

This is not just a Palo Alto story.

The broader lesson is that vulnerability discovery is shifting from scarce expert labor to model-accelerated scanning, triage, and exploit-path analysis.

Palo Alto Networks Update

The company disclosed the operational version of the same shift.

Palo Alto Networks said its May 2026 advisory was the first time the majority of findings came from frontier AI models scanning its code.

Initial scan130+

products across all three platforms.

Advisory26 CVEs

covered in May Patch Wednesday.

Issue count75

issues represented in the advisory.

Normal month<5 CVEs

typical monthly volume, according to Palo Alto Networks.

Executive Read

AI turns vulnerability discovery into a speed problem.

Companies used to rely on the fact that deep code review takes time. That assumption is weakening. Once discovery accelerates, slow remediation becomes the visible failure.

Legacy risk

Years of old code become searchable

AI can surface hidden defects across code that was never reviewed at modern speed or scale.

Patch bottleneck

Finding is easier than fixing

Security value depends on triage, ownership, testing, rollout, customer communication, and validation.

Team model

Humans are augmented

Security teams still judge impact, prioritize exposure, coordinate patching, and own outcomes.

Board Risk Shift

The risk moves from unknown defects to unowned remediation.

A better scanner can reveal more work than the organization is ready to fix. Leadership has to create a system for prioritizing and proving risk reduction.

What can break

  • Large finding backlogs with no product owner.
  • Externally reachable flaws buried inside old systems.
  • Patch delays because fixes cross team or supplier boundaries.
  • Customer, insurer, regulator, and board questions without evidence.

What has to improve

  • AI-assisted scanning across code, cloud, and dependencies.
  • Risk triage by exploitability and business impact.
  • Remediation lanes shared by security, engineering, and product.
  • Evidence packs that show what changed and what remains.
Operating Model

Turn AI scanning into a remediation machine.

The winning pattern is not a one-time model run. It is a recurring find, triage, patch, verify, and report loop.

1

Scan

Code, SaaS, customer-facing apps, dependencies, cloud exposure, and AI infrastructure.

2

Triage

Rank by reachability, exploit path, customer impact, privilege, and compensating controls.

3

Patch

Assign product, engineering, security, DevOps, legal, comms, and customer success owners.

4

Verify

Rescan after fixes, test regression, and validate that reachable risk actually went down.

5

Protect

Use segmentation, WAF, endpoint controls, virtual patching, monitoring, and response automation.

6

Report

Show surface area, risk trend, time-to-fix, residual exposure, and investment constraints.

Leadership Questions

The right questions are operational, not theoretical.

Boards and executives should ask for proof that model-speed discovery is being converted into customer-risk reduction.

QuestionWeak answerStronger answer
What was scanned?One repo or one app family.A named inventory of code, applications, dependencies, exposure, and cloud surfaces.
What matters most?Severity labels only.Reachability, exploit path, customer impact, privilege, and compensating controls.
Who owns fixes?Security creates tickets.Product, engineering, DevOps, and security share remediation lanes with dates.
How do we prove progress?Counts of closed issues.Validated fixes, residual risk, time-to-fix, and customer-facing exposure trend.
Final Takeaway

Find faster.
Fix faster. Prove faster.

The new security question is not whether AI can find flaws. It is whether the enterprise can absorb model-speed discovery without turning it into unmanaged operational risk.

© 2026 Chander Dhall Methodworks, LLC. All rights reserved.