AI Accelerates Vulnerability Discovery and Exploitation, Worsening Enterprise Security
New data from Google Threat Intelligence Group (GTIG) reveals that artificial intelligence is accelerating vulnerability discovery and exploitation, particularly in enterprise and critical infrastructure attack surfaces. The report found that vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August, while the average number of vulnerabilities exploited each month increased from 10.5 in 2025 to 18 between January and August 2026.
The growth in exploitation was driven primarily by the rapid weaponization of high-risk, previously disclosed vulnerabilities, rather than a major increase in zero-day exploitation. GTIG noted that AI-assisted vulnerability discovery is producing a different risk profile, with AI-discovered vulnerabilities showing a higher proportion of Medium- and High-Risk findings.
From January through August 2026, 58% of identified AI-discovered vulnerabilities were rated Medium risk, compared to 28% among vulnerabilities not discovered by AI. GTIG also found that autonomous research agents can uncover high-severity flaws when directed at critical attack surfaces.