AI Patching Shifts the Bottleneck to Review

OpenAI is pushing AI security work past bug finding and into patch generation, which moves the choke point from discovery to human review. The real limit is no longer how many flaws a tool can surface. It is how many machine-suggested fixes a team can validate, deduplicate, and safely merge before they touch production. OpenAI released GPT-5.5-Cyber, updated Codex Security, and launched Patch the Planet with Trail of Bits to help trusted defenders and open-source maintainers validate issues and draft patches at scale. OpenAI says Codex Security has scanned more than 30 million commits across 30,000 codebases, with more than 500,000 findings resolved automatically and tens of thousands of fixes confirmed by humans. For teams already using AI-assisted scanning or patching, the operational risk is a growing review queue, not a new exploit class. Faster intake can outpace the capacity to inspect fixes, and that makes quality control the scarce resource.

Part of the PlainSec briefing for 2026-06-27

Sources