Security teams achieved a 75% year-over-year reduction in exploitable in-use vulnerabilities, but CVE growth is exponential and AI is collapsing the window between vulnerability disclosure and weaponization — from nearly a year in 2018 to hours in 2025-2026. The 5% ceiling on in-use vulnerabilities without known exploits has plateaued, signaling human-scale defenses are insufficient. The argument is that agentic AI with human-defined guardrails (scoped permissions, deterministic rollbacks, audit logs, risk thresholds) is becoming operationally necessary, drawing parallels to how CI/CD and automated response were once controversial but are now standard practice.
Table of contents
An exponential growth in vulnerabilitiesAI is changing how we think of vulnerabilitiesThe next step in automationThe importance of AI guardrailsConclusion6 Impressions