www.darkreading.com 9 Sept 2026, 21:19 UTC

AI Finds Thousands of Flaws, but Humans Patch Fewer Than 1%

CyberSIXT Evidence Panel Source marked as original reporting

A new analysis of public data from Anthropic’s Project Glasswing shows a widening gap between AI-generated vulnerability findings and those that actually reach disclosure or remediation. The Claude Mythos model produced 26,153 findings across various software projects since Glasswing began in April 2026, but only about 2,736 of these have appeared in Anthropic’s Vulnerability Disclosure Ledger, i.e., slightly more than 10%.

In practical terms, fewer than 0.8% have been patched (around 202), with 245 withdrawn and 191 still in pre-disclosure. This suggests that human validation and coordination are the bottlenecks in determining which AI-generated flaws warrant disclosure and remediation, rather than the discovery of flaws themselves.

The analysis also casts doubt on Mythos’s reported accuracy and severity assessments. Of the findings that made it to the ledger, Claude marked 91.4% as true positives, but the number of fixed vulnerabilities was far lower than the 245 withdrawn cases, prompting questions about how severity is determined. Claude reportedly deemed 91.5% of ledger findings as critical or high, while maintainers judged only 61.3% as matching that severity.

Researchers emphasise the need for standardised metrics (CVSS scores, CWEs) to interpret AI-generated weakness reports. The piece frames this as part of a broader challenge: AI can accelerate discovery, but the economics and logistics of triage, validation, and patching may keep vulnerability management effectively at human speed.

View full article

Article by CyberSIXT