"We've never had a situation where massive codebases have been audited to that level before," Gartner research vice president Craig Lawson told The Register.
Lawson's thesis at Gartner’s IT Symposium in Australia
Speaking at Gartner’s IT Symposium in Australia, Lawson laid out a simple but consequential idea: the sudden flood of vulnerability discoveries driven by AI-powered bug-hunters could be shepherding long-neglected code toward a cleaner state. He argued that tools such as Anthropic’s Mythos — and other automated bug-hunting systems — are enabling a scale of audit previously unseen, and that this surge of findings is already retiring what he called technical debt.
Lawson pointed to recent, concentrated discovery activity and said, “Think about how much technical debt has been retired in products just in the last six months.” That retirement, he suggested, may change not only the quantity of reported vulnerabilities but their quality — the severity of the remaining flaws.
Anthropic’s Mythos, AI bug-hunters, and the 2026 spike in disclosures
Lawson framed the recent spike in public disclosures — highlighted by one vendor delivering over 970 patches in a single week — as a transitional shock rather than a permanent rise. He told The Register that the sheer volume of discoveries is consistent with powerful automated scrutiny being applied to mature codebases for the first time. He argued that this creates two linked effects: a backlog of known, fixable issues being reported now, and better vetting of new releases as vendors adopt the same AI techniques internally.
He also noted that security vendors themselves are using AI to find flaws in their own products, and that those vendor-driven discoveries further reduce potential avenues for zero-day attacks.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleOpenBSD CVEs as a signal, not an anomaly
Lawson singled out the recent series of CVEs found in OpenBSD — “an unusually secure and stable OS,” in his words — as evidence of AI-powered audit reach. The point was not to single out OpenBSD for criticism, but to underline how deep automated scanning now penetrates: if a historically robust codebase is yielding new findings, larger, older products are unlikely to remain untouched.
That dynamic supports his broader claim that the 2026 volume of CVEs is a positive signal of cleanup activity, potentially followed by a reduction in severity metrics as remediation completes.
Daily red teams, virtual patches and a different SOC metric
Beyond discovery, Lawson described how AI could shift day-to-day defensive work. He argued that red-team exercises — today “infrequent and costly” and usually outsourced — could become routine if AI-driven bug-hunters are available internally. That would let organizations “effectively run a red team every day,” he said.
Lawson further suggested that AI could shorten the time from finding a problem to applying a fix. He offered a concrete example: “What if I could spend three minutes going to Gemini and saying ‘Write syntax for an F5 IRule’ that becomes a virtual patch? Everyone can do threat intelligence, enrichment, some of those harder tasks.”
On measurement and morale, Lawson urged a shift away from counting closed tickets toward celebrating operational impact — “the fact that cyber-defenders kept a hospital open or stopped a ransomware raid,” he told The Register — arguing that impact-based recognition better reflects defensive success.
What this means for technologists and security teams, SOCs and hospital operators, and security vendors and procurement leaders
- Technologists and security teams: Expect a wave of remediation work as AI-generated findings surface flaws; Lawson’s view signals a near-term busy period of fixes and a possible medium-term decline in severe vulnerabilities.
- SOCs and hospital operators: Lawson urged measuring success by operational continuity — for example, keeping a hospital open — rather than ticket throughput, suggesting priorities and KPIs may shift if virtual patches and faster fixes become practical.
- Security vendors and procurement leaders: Vendors are already using AI to test their own products, Lawson noted; procurement leaders should watch whether those tools become standard practice and whether they materially reduce severity in future releases.
Lawson concluded with a cautious forecast: “2027 could be the first year we see a net drop, maybe not in aggregate vulnerabilities, but definitely in severity of flaws.” The record for 2026 — the deluge of discoveries and the high patch counts — may therefore be the noisy, necessary prelude to a calmer, less dangerous year. Whether vendors adopt AI testing comprehensively, and whether organizations embrace daily, AI-driven red teaming and the KPI changes Lawson recommends, remain practical questions that will decide if 2027 becomes the relief he envisions.




