Summary
- Only 1% of AI-discovered vulnerabilities have been observed being exploited in the wild, according to VulnCheck research.
- The current balance favours defensive vulnerability research over offensive exploitation when it comes to AI-assisted work.
- A VulnCheck researcher has stated explicitly that AI benefits vulnerability research more than it benefits exploitation at this time.
- The findings suggest a window of opportunity for organisations to act on AI-surfaced vulnerabilities before threat actors weaponise them.
- The research does not address how long this defensive advantage will hold as attacker AI capabilities mature.
The numbers in context
Research published by VulnCheck has put a concrete figure on something the security industry has largely debated in qualitative terms: of the vulnerabilities being uncovered with the assistance of AI tooling, only one per cent have been observed exploited in the wild. That is a low conversion rate, and it carries meaningful implications for how security leaders should be thinking about AI’s current role in the threat landscape.
Defenders ahead — for now
The headline finding from VulnCheck is straightforward. According to the researcher behind the analysis, AI is presently delivering more value to those hunting for vulnerabilities defensively than it is to those seeking to exploit them offensively. That asymmetry, if it holds, represents a genuine operational advantage for security teams that are actively using AI in their vulnerability research and triage workflows.
What the gap actually means
A 99% non-exploitation rate across AI-discovered vulnerabilities is not an argument for complacency. It reflects a lag — the time between a vulnerability being identified, potentially disclosed, and then weaponised by threat actors. Security teams that move quickly during that window can patch, mitigate, or implement compensating controls before the vulnerability becomes a practical attack vector. The research effectively quantifies that window as being wider than many in the industry may have assumed.
The research does not tell us everything
It is worth being clear about what the VulnCheck findings do not cover. The source material does not specify the total volume of AI-discovered vulnerabilities in the dataset, the timeframe over which exploitation was measured, or the industries and asset types most represented in the research. It also does not address whether that one per cent figure is trending upward as attacker tooling matures. CISOs should treat this as a directional signal rather than a comprehensive threat model.
The attacker side of the equation
The research framing is careful and measured: AI currently benefits defenders more than attackers in this specific context. That is not the same as saying AI poses no offensive risk. The security industry has documented growing use of AI in phishing, social engineering, and reconnaissance. The VulnCheck finding is scoped to vulnerability exploitation specifically, and it should be interpreted within those boundaries.
An opportunity that requires active pursuit
The practical upshot for security executives is that the current landscape rewards investment in AI-assisted vulnerability discovery and rapid remediation cycles. Organisations that are surfacing vulnerabilities through AI tooling and acting on them faster than adversaries can develop working exploits are in a structurally better position than those relying solely on traditional scanning cadences or waiting on vendor patch cycles. The research supports a case for accelerating that capability.
Why it matters
For CISOs, this research offers a rare data point that is genuinely reassuring without being dismissive of risk. The one per cent exploitation rate suggests that AI-discovered vulnerabilities are not being rapidly turned against organisations at scale — yet. That creates a measurable remediation window that security teams can act within. The strategic implication is that investing in AI-assisted vulnerability research now, while defenders hold the advantage, is likely to deliver better risk reduction outcomes than waiting. The unknown is how durable this advantage is as attacker capabilities continue to develop, and that uncertainty is itself a reason to move with purpose rather than wait for the gap to close.
What to do now
- Assess whether your vulnerability research and triage workflows are incorporating AI-assisted tooling to take advantage of the current defensive edge identified in the research.
- Prioritise rapid remediation cycles for vulnerabilities surfaced through AI discovery methods, using the exploitation lag documented in the research as a planning input.
- Treat the one per cent exploitation figure as a point-in-time baseline and monitor VulnCheck and comparable sources for updates to that rate as attacker AI capabilities evolve.
- Avoid interpreting the low exploitation rate as a signal to deprioritise AI-discovered vulnerabilities — the research identifies an advantage, not an absence of risk.
