Gil Geron, chief executive and co-founder of Orca Security, answered Lets Data Science in writing about what AI-driven vulnerability discovery changes for enterprise security teams. His central claim is that finding vulnerabilities is no longer the limiting factor, and that the bottleneck has moved to remediation. Orca's 2026 State of AI Security Report, published in July, found that 99 percent of alerts with an available fix remain unpatched and that 81 percent of organizations using AI packages carry at least one known vulnerability, both company research. Geron argues defenders hold a slight edge today through responsible disclosure, that the advantage will shift to execution as discovery becomes cheap for everyone, and that the under-appreciated risk is AI letting almost anyone inside a company build software.
2026 State of AI Security: AI Is in Production. Security Isn't.