A recent survey of risk managers, auditors, and senior executives across 316 companies has identified AI-driven cyber vulnerability discovery as the most impactful emerging risk. This finding represents a significant shift from a similar survey conducted three months prior, where this particular risk was not even among the top five.
The elevated concern stems from two key developments: the ability of AI systems to identify previously unknown flaws at a scale that overwhelms traditional patching capabilities, and the dramatic reduction in the time and effort required to develop functional exploit code from a discovered vulnerability. Historically, crafting exploits was a significant barrier for many attackers, but AI has largely removed this hurdle.
This accelerated discovery rate means defensive teams are facing a rapidly expanding backlog of unpatched critical vulnerabilities within increasingly complex systems due to AI integration. AI models have shown improved proficiency in generating working exploits, prompting vendors to form defensive partnerships, such as Anthropic's Project Glasswing and OpenAI's Daybreak, to proactively identify and patch exploitable code.
Respondents to the survey assigned a time frame score of 1.92 to this risk, indicating an average expectation of tangible impact within one to two years. A substantial 76% of participants placed it in their top ten emerging risks, with it ranking first across all four global regions: 78% in Europe and Asia-Pacific, 75% in the Americas, and 70% in the Middle East and Africa. Within specific industries, 78% of banking, financial services, and insurance respondents highlighted it, compared to 74% in other sectors.
Despite ranking AI vulnerability discovery as the highest impact risk, respondents also paradoxically rated their organizations as most prepared for it. This self-reported preparedness, on a five-point scale where the highest mark signifies active discussion and implemented steps, does not account for the actual capabilities of AI in accelerating vulnerability discovery.
This discrepancy suggests several critical actions for organizations. First, the impact assigned to cyber risk needs recalibration, as faster discovery inherently increases third-party, business continuity, and legal exposures. Second, organizations must revisit their risk appetite for continuous exposure and establish clear policies on how long a vulnerability can remain unpatched. Third, vendors should be required to provide stronger security validation regarding their own potential compromises. Finally, vulnerability management strategies must evolve towards faster, more automated remediation processes.
Interestingly, AI vulnerability discovery did not feature among the top five risks identified by respondents as offering the most business upside. Those risks included AI-driven competitive displacement, agentic AI, AI-driven skill erosion, AI intellectual property control, and U.S. financial deregulation, highlighting a clear distinction between perceived threats and opportunities related to AI.






