Gartner’s quarterly survey of 316 security and risk leaders put AI-enabled vulnerability discovery at the top emerging risk for 2Q26. Respondents also said it is the one they feel most prepared for, with 76% placing it in their top ten.
The mechanism is simple: AI can scan huge amounts of code for flaws and then generate working exploit code quickly, so the old gap between finding a bug and weaponizing it has shrunk to almost nothing. That turns unpatched vulnerabilities into a faster-moving attack queue, especially where remediation already lags.
For teams with long patch cycles or internet-facing systems, the exposure is less about how many bugs exist than how quickly they can be cleared. The survey points to a control problem: if remediation cannot keep pace, the backlog itself becomes the attack surface.