AI can find zero-days but still can’t reliably write secure code
Summary
Large language models (LLMs, AI systems trained on massive amounts of text) are getting better at finding zero-day vulnerabilities (previously unknown security flaws) and creating exploits, but they are not improving at writing secure code or creating reliable patches for those vulnerabilities. Studies show that AI-generated code contains security flaws at roughly double the rate of human-written code, with 44% of AI code containing at least one known OWASP Top 10 vulnerability (a list of the most dangerous code weaknesses), yet AI still produces syntax-correct code 99% of the time, raising questions about why AI excels at some security tasks but fails at others.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4210735/ai-can-find-zero-days-but-still-cant-reliably-write-secure-code.html
First tracked: August 18, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%