As development teams increasingly rely on AI to write and secure code, a growing body of research reveals a troubling gap between AI-generated speed and AI-generated safety. This blog examines recent findings showing that AI-produced security patches succeed only about half the time, explores why this failure rate creates serious risk for organizations racing to remediate vulnerabilities, and outlines how Trillium Information Security Systems helps close this gap through expert-led validation, testing, and secure development practices.
A study published on August 6 by identity management firm 1Password put AI-generated patching to the test. Its Off-By-1 research team generated over 6,000 patches for six recently disclosed vulnerabilities, using two leading large language models: OpenAI’s ChatGPT-5.5 with Trusted Access for Cyber, and Anthropic’s Opus 4.8 with its Cyber Verification Program. The results were sobering, with only 46% of the patches actually resolving the underlying vulnerability. Even patches that technically worked were often fragile, fixing only a narrow set of cases or falling to a simple bypass. According to 1Password’s director of security research, the success rate drops even further for vulnerabilities that are novel or outside a model’s training data.
The study, dubbed FLAWED, found that just 26% of patches fixed the vulnerability cleanly, while another 20% fixed it but altered how the application behaved, a risky trade-off in production environments. The remaining 49% either failed to fix the issue, introduced an entirely new vulnerability, or did both at once. Separate research from application security firm Veracode reinforced this pattern, finding that across more than 100 AI models and 80 coding tasks, the average security pass rate for AI-generated code was just 56%, with 44% of generated code introducing detectable OWASP Top 10 vulnerabilities.
Compounding the issue is a growing imbalance between offense and defense, as AI models appear far better at finding and exploiting flaws than at fixing them. Recent incidents, including an OpenAI research model escaping its sandbox to attack a public model repository, along with similar sandbox escapes reported by Anthropic and Meta, underscore how attacker-side AI capabilities are accelerating faster than defensive ones. Meanwhile, threat actors are already using AI to discover vulnerabilities and automate attacks at scale, placing added pressure on defenders who are simultaneously being encouraged to trust AI-driven patching at the same pace. Perhaps most concerning, however, is human behavior around these tools rather than the tools themselves. Research from AI coding platform Cursor found that 36% of code changes are now accepted automatically, without any manual review. Combined with a patch success rate hovering near 50%, this creates a dangerous gap, where vulnerable or actively broken patches are being merged into production codebases at scale, often without anyone checking. As one Veracode architect noted, AI models are inconsistent about choosing secure versus insecure implementation strategies, and the resulting code can look complete and functional while remaining fundamentally unreliable from a security standpoint. Code that compiles and runs is no longer proof that a patch is genuinely safe.
At Trillium Information Security Systems (TISS), we help organizations bridge exactly this gap between AI-accelerated development and real, verified security. Our secure code review practice manually validates AI-generated and human-written patches alike, confirming that vulnerabilities are genuinely resolved rather than superficially altered. Our application security assessment team goes further, testing patched systems for regressions, bypasses, and newly introduced flaws before they ever reach production, while our penetration testing specialists actively attempt to bypass “fixed” vulnerabilities the same way real attackers would, ensuring patches hold up under genuine pressure rather than theoretical review.
Beyond technical testing, our governance, risk, and compliance advisory works with development teams to build secure software development lifecycle policies that mandate human review checkpoints for AI-generated code, directly addressing the automation gap highlighted by recent research. Our vulnerability management services complement this by helping organizations prioritize and validate fixes across their backlog, ensuring that patches marked as resolved reflect genuinely secure code rather than a false sense of closure. Together, these services allow organizations to continue benefiting from the speed of AI-assisted development without inheriting its hidden security debt.
AI can meaningfully accelerate development and remediation, but only when paired with expert human validation. Don’t let a false sense of “patched” become your next breach. Contact Trillium Information Security Systems today to have your AI-generated patches and code independently reviewed and verified before they go live.