AI might fix code so fast we won't need security teams

INDUSTRY PERSPECTIVE

Source: The Register, October 27, 2025  |  Analysis by AirGap Labs

We Don't Have a Cybersecurity Problem. We Have a Software Quality Problem.

Former CISA Director Jen Easterly made a striking claim at AuditBoard's 2025 conference in San Diego: if AI is deployed and governed correctly, it could lead to the end of cybersecurity as we know it. Not the end of security - the end of breaches as a cost of doing business.

The Argument That Reframes Everything

Easterly's core thesis is blunt: the reason cybercriminals succeed isn't because they're brilliant - it's because the software they're attacking is riddled with preventable vulnerabilities. Vendors have spent decades prioritizing speed to market and cost reduction over security, and attackers have made a trillion-dollar industry out of the predictable result.

If cybercrime were a country, she noted, it would be the third-largest economy on earth - behind only the US and China. That scale exists almost entirely because of bad software, not sophisticated adversaries. Easterly's pointed suggestion that hackers be renamed from "Fancy Bear" to "weak weasel" and "Scattered Spider" to "scrawny nuisance" captures the point: we've been mythologizing attackers who are exploiting problems we created ourselves.

Where AI Changes the Equation

AI, Easterly argued, is the first technology capable of finding and fixing vulnerabilities at a scale and speed that humans simply cannot match. Defenders have always been playing catch-up - patching after exploitation, responding after breach. AI has the potential to flip that dynamic: finding vulnerabilities before attackers do, at machine speed, across entire codebases.

CISA has developed its own AI action plan around exactly this vision. The White House AI Action Plan echoes it, specifically calling for AI systems built with security as a top priority - not bolted on afterward. If that vision is realized, Easterly believes a security breach could become an anomaly rather than an inevitability.

#3

Cybercrime's rank as a global economy, behind only the US and China

1,000+

CISA staff lost since 2025 - one third of its workforce

3 days

Proposed new KEV patch deadline, down from 2-3 weeks

The Tension Nobody Wants to Talk About

Easterly's optimism lands in uncomfortable context. While she was making this case in San Diego, CISA was quietly losing a third of its workforce. The agency that coordinates threat intelligence across 102 federal agencies, runs the Known Exploited Vulnerabilities catalog, and serves as the early-warning system for critical infrastructure operators went from 3,400 to roughly 2,400 staff. Its proposed FY2026 budget carries a 17% cut.

Former NSA cybersecurity director Rob Joyce put it plainly in a separate webinar: AI systems are now finding software vulnerabilities at industrial scale. "We're not finding bugs faster because we have more humans on the problem. We're finding them faster because the discovery loop is now mostly machine." That cuts both ways. Defenders can use it. So can attackers. And in May 2026, Google confirmed the first AI-generated zero-day capable of bypassing two-factor authentication - found, weaponized, and deployed without human direction.

Easterly's vision of AI as the great equalizer assumes the defense side has the resources, access, and institutional infrastructure to actually deploy it. Right now, that assumption is under pressure.

What This Means for Organizations Like Yours

The "secure by design" principle Easterly champions is not just a software vendor problem. It applies to every organization that selects, deploys, and integrates technology. If you're running infrastructure built on code that prioritized cost over security - and most organizations are - the AI-accelerated discovery cycle means your exposure window is shrinking faster than your patching cadence.

A few things that follow from Easterly's framework:

  • Patch velocity matters more than it ever has. CISA's move toward 3-day KEV deadlines reflects the reality that AI-accelerated exploitation compresses the window between disclosure and active attack.
  • Legacy systems are the real liability. AI is particularly effective at finding exploitable flaws in older, unmaintained code. End-of-life systems that were manageable risks a year ago are increasingly dangerous.
  • AI on the defense side isn't optional. If attackers are running machine-speed vulnerability discovery, defenders running human-speed response are structurally disadvantaged. This is the case for AI-powered security tooling - not as a nice-to-have, but as a baseline requirement.
  • Fortinet's AI Security Fabric is built for exactly this moment. FortiAI, FortiGuard's AI-driven threat intelligence, and FortiSIEM's behavioral analytics are the defensive equivalent of what Easterly is describing: machine-speed detection, response, and vulnerability identification running continuously across your environment.

The AirGap Labs Take

Easterly is right about the diagnosis. We do have a software quality problem, and AI will accelerate both the exposure of that problem and - if deployed properly - its resolution. The end of cybersecurity she's describing isn't utopian; it's engineering. Make the software good enough, fast enough, and breaches become anomalies instead of inevitabilities.

But "if we get this right" is doing a lot of work in that sentence. Getting it right requires defenders to have the tools, the staffing, and the institutional support to actually run AI-powered security at scale. For most organizations, that means making deliberate choices now - about what technology they're running, how fast they can respond to emerging threats, and whether their security stack can operate at machine speed.

That's the conversation we have with every client. Not whether AI changes the threat landscape - it already has - but whether their defenses are positioned to take advantage of the same capabilities their adversaries are already using.

Source: The Register - Ex-CISA chief says AI could mean the end of cybersecurity (October 27, 2025)

Additional reporting: Axios, Federal News Network, Cloud Security Alliance

AirGap Labs  |  Irvine, CA  |  airgaplabs.com

Back to blog