AI Can Find Zero-Days but Still Can't Reliably Write Secure Code
CSO Online, Tuesday, August 18th, 2026
CSO Online examines a widening asymmetry between AI's offensive vulnerability discovery and its defensive code quality.
CSO Online examines a growing cyber asymmetry as AI models' offensive and defensive capability gaps diverge.
In recent months LLMs have moved from flooding open-source projects and bug bounty programs with questionable security reports that wasted developer time, to routinely finding zero-day flaws that humans and traditional audit tools had missed for years.
That rapid evolution alarms even the models' own creators. Despite the advances in vulnerability discovery, the same models still cannot reliably write secure code. The article argues this leaves enterprises facing attackers who benefit more from AI than defenders currently do.