AI finds a lot of "vulnerabilities" but most are fake, untested, or not actually vulnerabilities.
Reminder that AI is quite stupid.
It may have a high false positive rate, but at the speed AIs can review code, there's still plenty, of real vulnerabilites mixed in with the garbage.
I'll trust the words of groups like curl (https://daniel.haxx.se/blog/2026/06/10/a-human-in-control/), Linux, and even the infamously anti-AI Gnome (https://blogs.gnome.org/mcatanzaro/2026/10/02/the-era-of-sof...) that AI is finding real vulnerabilities and you're your project a disservice by ignoring them.
Edit: Though Greg did recently have a talk (that I skimmed) where he was a little reserved on LLMs: https://www.youtube.com/watch?v=NnV_cWeoo5Q
I think this is just plain denial, AI has found many high severity vulnerabilities.
It may have a high false positive rate, but at the speed AIs can review code, there's still plenty, of real vulnerabilites mixed in with the garbage.
I'll trust the words of groups like curl (https://daniel.haxx.se/blog/2026/06/10/a-human-in-control/), Linux, and even the infamously anti-AI Gnome (https://blogs.gnome.org/mcatanzaro/2026/10/02/the-era-of-sof...) that AI is finding real vulnerabilities and you're your project a disservice by ignoring them.
Edit: Though Greg did recently have a talk (that I skimmed) where he was a little reserved on LLMs: https://www.youtube.com/watch?v=NnV_cWeoo5Q