- Vulnerability exploitation is now the top initial access vector for breaches, at 31%, while the median time to fully remediate has slipped from 32 days to 43 (Verizon 2026 DBIR).
- Frontier AI cuts both ways. Defenders surface exposure faster, and adversaries compress the time available to respond. CrowdStrike recorded a 27-second fastest breakout in 2025.
- The constraint has moved from finding vulnerabilities to fixing them. A longer findings list does not make an enterprise safer.
- AI earns its place in four steps: validation, prioritization, fix generation and verification. Security and engineering teams still approve every change that reaches production.
- Presidio AI Code Defense pairs continuous assessment with a remediation pathway that delivers validated, ready-to-merge pull requests, backed by governed access through OpenAI’s Trusted Access for Cyber and Anthropic’s Cyber Verification Program.
Enterprise security teams have spent years working through a familiar pattern: scan for vulnerabilities, review the findings, prioritize the most urgent issues and send remediation work to teams that already have full backlogs.
That process was under strain before frontier AI became part of the cybersecurity conversation. Now, the gap is becoming even harder to manage.
Advanced AI models are changing what is possible for both defenders and adversaries. Security teams can use these new capabilities to surface risk faster, validate findings with more context and understand exposure across complex environments. Meanwhile, attackers can use similar advances to move faster across the attack lifecycle, lower the expertise required to exploit weaknesses and compress the time organizations have to respond.
That puts added pressure on one of the hardest aspects of cybersecurity: turning findings into fixed, validated outcomes.
Many organizations can already find more vulnerabilities than their teams can act on. The harder challenge is whether security and engineering teams can close the loop from discovery to remediation fast enough to reduce real risk.
The window from discovery to exploitation is shrinking
Remediation capacity is moving the other way. The Verizon 2026 Data Breach Investigations Report found vulnerability exploitation is now the top initial access vector for breaches at 31%, ahead of credential abuse at 13%. Only 26% of vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% a year earlier, and the median time to full remediation rose from 32 days to 43.
Independent voices reading the same data point to the same fix. Phyllis Lee, Vice President of Security Best Practices Content Development at the Center for Internet Security, told Help Net Security that defenders should focus on “proven, prioritized security controls and timely remediation.”
Recent industry data shows how quickly the threat environment is moving. According to CrowdStrike’s 2026 Global Threat Report, AI-enabled attacks grew 89% year over year, and the fastest recorded eCrime breakout time dropped to 27 seconds. Additional research points to the same larger shift: enterprise codebases are growing more AI-assisted, while the pace of AI-enabled intrusion and data exfiltration continues to accelerate.
Those numbers matter because they expose a mismatch between the speed of modern threats and the cadence of many vulnerability management programs. Quarterly scans, annual assessments and manual remediation cycles were not designed for an environment where adversaries can use AI to discover, test and act on weaknesses at this pace.
Frontier AI also changes the scale of discovery. In one example, an AI-enabled scan surfaced far more exposure than expected. The organization anticipated a worst-case result in the range of 10,000 to 20,000 vulnerabilities. The scan identified millions of theoretical entry points, underscoring how quickly AI-enabled discovery can overwhelm traditional triage and remediation workflows.
That kind of output creates a new operational challenge. A longer list of findings does not automatically make an organization more secure. Instead, security teams need to know which issues are confirmed, which are exploitable, which create meaningful business risk and which can be addressed first without overwhelming engineering.
The organizations that benefit most from AI-enabled security will be the ones that pair faster discovery with a reliable remediation model.
Faster findings require a better operating model
Traditional vulnerability management often breaks down at the handoff between security and engineering. A security team identifies a weakness, creates a ticket or shares a report, then relies on another team to interpret the finding, determine the right fix, schedule the work, test the change and prove the issue was resolved.
Every handoff creates delay. Every unclear finding creates debate. Every false positive erodes trust between security and developers. Over time, the backlog grows, developers get pulled away from product work and leaders struggle to show whether security posture is actually improving.
Frontier AI makes those breakdowns more visible because discovery gets faster. When findings arrive at machine speed, organizations cannot depend on manual triage and ad hoc remediation to keep up.
A stronger model connects the full workflow: discovery, validation, prioritization, remediation, verification and reporting. That means teams can move from “we found an issue” to “we fixed the issue, validated the result and can show progress over time.”
This is the core opportunity for AI-enabled defense. AI has the power to help security teams focus on what matters, help engineers move faster and help leaders see measurable improvement instead of a growing list of unresolved risk.
Where AI can help in the remediation process
AI can also play an important role in remediation, especially in areas where scale and repetition slow teams down.
Validation
Security tools often generate findings that require manual review before teams know whether action is needed. AI can help evaluate code context, reachability, attack paths and business relevance so teams can separate confirmed risk from noise. In Presidio’s AI Code Defense model, findings are reviewed through dual frontier AI models and specialized agents, then validated by Presidio security analysts before reaching the client team.
Prioritization
Many organizations still prioritize based heavily on severity scores, even though a high-severity issue may not always represent the most likely or damaging path for an attacker. AI can help enrich findings with exploitability, reachability and environmental context, giving teams a more practical view of what needs attention first.
Generation
Once a finding is confirmed, AI can help create a remediation path that engineering teams can review. Presidio’s remediation pathway is designed to deliver validated, ready-to-merge pull requests directly to engineers. This keeps developers in control of every change, while the manual effort required to research and draft fixes is reduced.
Verification
A remediation process should not end when a ticket is closed. AI-enabled workflows can re-scan, test and retry when a fix fails, then provide documentation that shows how the issue was addressed. This gives security, engineering, audit and executive teams a clearer record of progress.
Analysts land in the same place. Gartner’s top cybersecurity trends for 2026 put oversight of agentic AI at the head of the list, and Gartner predicts AI applications will drive 50% of incident response work by 2028. Alex Michaels, Director Analyst at Gartner, put the requirement directly: cybersecurity leaders “must prioritize people as much as technology.”
Human judgment remains central to this process. AI can accelerate analysis and propose fixes, but security experts and engineering teams need to govern what gets acted on, approve changes and make context-specific decisions before code reaches production. A human-governed model gives organizations a way to use AI for speed without giving up control.
Why governed access matters
The most advanced cyber-capable AI models are being handled differently from standard enterprise AI tools. Because these models can support legitimate defensive work and potentially harmful activity, access is being managed through selective, governed programs.
Presidio’s participation in OpenAI’s Trusted Access for Cyber program and Anthropic’s Cyber Verification Program strengthens its ability to apply frontier AI responsibly to defensive cybersecurity workflows. Through OpenAI TAC, Presidio’s cybersecurity teams gain governed access to advanced cyber capabilities, including OpenAI’s Daybreak cyber models where approved. Anthropic CVP provides a verified pathway for legitimate defensive work that may overlap with dual-use cyber tasks, including vulnerability research, penetration testing, red teaming, threat analysis and controlled validation.
“Attackers are already operating at AI speed. Our participation in OpenAI TAC and Anthropic CVP allows Presidio to put governed frontier AI cyber capabilities directly into delivery, helping clients identify, prioritize, and close exposures faster than adversaries can exploit them,” said Dustin Harriman, Senior Director, Cybersecurity Services at Presidio. “These programs give our teams a responsible path to apply advanced AI to real-world defensive outcomes.”
For clients, the significance goes beyond model access. The larger value is having a partner that can translate frontier AI capability into a practical delivery model with safeguards, oversight and measurable outcomes.
“Our clients look to us to translate emerging AI capability into measurable risk reduction,” said Justin Tibbs, Vice President of Cybersecurity at Presidio. “OpenAI TAC and Anthropic CVP give our architects, threat detection engineers, and red teamers governed, verified paths to apply frontier AI where it matters most: finding, validating, prioritizing, and remediating the vulnerabilities that put enterprises at risk without compromising on safety, accountability, or trust.”
Remediation needs to fit the way enterprises actually operate
Most remediation programs do not fail because people misunderstand the risk. They fail because the work is difficult to operationalize across real enterprise environments.
A vulnerability may live in code, but resolving it can require knowledge of the application, the architecture, the development pipeline, the business process it supports and the compliance requirements around it. Security teams need confidence that a finding is legitimate. Engineering teams need fixes that will not break builds or slow delivery. Risk and compliance teams need documentation that supports audits, insurance renewals and board reporting.
That is why Presidio’s cyber-led model is important. Presidio works across cybersecurity, cloud, infrastructure, application development, managed services and digital transformation. That broader view matters because remediation often crosses multiple technical and business domains.
Presidio AI Code Defense is built around two connected pathways. The assessment pathway continuously surfaces validated, priority-ranked findings from source code, while keeping the client’s code inside the client environment. The remediation pathway turns validated findings into ready-to-merge pull requests that engineering teams review and approve.
That structure addresses one of the biggest problems in vulnerability management: findings that are documented but never resolved. By connecting assessment and remediation in a governed workflow, organizations can reduce the gap between what is discovered and what is actually fixed.
From periodic patching to continuous improvement
The organizations best prepared for frontier AI will be the ones that make remediation part of their normal operating rhythm.
That means moving away from episodic programs that produce point-in-time reports and toward continuous workflows that show measurable improvement over time. It also means giving leaders a clearer way to understand progress. Metrics such as mean time to remediate, fix coverage by vulnerability class, false-fix rate and month-over-month backlog reduction can help security and engineering teams show whether the program is working.
There is a business case for that kind of operating discipline. IBM’s 2025 Cost of a Data Breach research found that organizations with AI and automation in security saved $1.9 million per breach and reduced the breach lifecycle by 80 days. DevSecOps programs were also associated with breach cost reduction. These outcomes point to a practical reality: faster, better-governed remediation can reduce risk while helping teams use their time more effectively.
Security leaders also need evidence that will stand up to board, audit and insurance scrutiny. A report that lists unresolved findings is not the same as a documented trajectory of improvement. When findings are validated, mapped to compliance frameworks, remediated and tracked over time, the organization has a stronger story to tell about resilience.
Frontier AI raises the stakes because it reduces the time available to respond. It also gives defenders new ways to modernize how security work gets done. With the right governance, AI can help organizations move from discovery overload to validated action.
For many enterprises, the next step is to evaluate whether their current vulnerability management and remediation workflows are calibrated for this new environment. If discovery accelerates while remediation remains manual, fragmented and slow, risk will continue to accumulate.
The goal is to make remediation a repeatable discipline: find what matters, validate the risk, fix it through a governed process and prove that the organization is getting stronger over time.
Sources
- CrowdStrike, 2026 Global Threat Report. https://www.crowdstrike.com/en-us/global-threat-report/
- Verizon, 2026 Data Breach Investigations Report. https://www.verizon.com/business/resources/reports/dbir/
- Gartner, Gartner Identifies the Top Cybersecurity Trends for 2026, February 5, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026
- Gartner, Gartner Predicts AI Applications Will Drive 50% of Cybersecurity Incident Response Efforts by 2028, March 17, 2026. https://www.gartner.com/en/newsroom/press-releases/2026-03-17-gartner-predicts-ai-applications-will-drive-50-percent-of-cybersecurity-incident-response-efforts-by-2028
- IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach
- Help Net Security, Verizon DBIR: Vulnerability exploitation is the dominant initial access vector, May 20, 2026. https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/


