"Patch and release" security is dead. AI assisted attackers will have come, stolen, and gone before the patch gets out. Developers need to get this.
So is "swiss cheese" security. AI systems have the patience and breadth of skill set to work their way through layers of weak security. Attacks that used to take funded teams can now be carried out by individuals.