In a stunning demonstration of the speed of modern AI, researchers have shown that a large language model can take a standard security patch and turn it into a working exploit — in under thirty minutes. This development, reported by The Decoder on May 11, 2026, is sending shockwaves through the cybersecurity community. It doesn't just speed up the arms race between defenders and attackers; it fundamentally breaks one of the most cherished practices in vulnerability management: the 90-day responsible disclosure window.
For decades, the industry has operated on an unwritten rule. When a security researcher finds a flaw in software, they report it to the vendor privately. The vendor then has 90 days to create and release a patch before the researcher publicly reveals the vulnerability details. This gave everyone time to update their systems. But now, AI can exploit the patch itself in minutes, using the very fix as a blueprint for the attack. The old timeline is dead.
This article breaks down what this means for the future of AI, how it will be used by both attackers and defenders, and the critical actions businesses and society must take right now.
The research, conducted by a team of security experts, used a state-of-the-art AI model to analyze patches released for popular software. The process is eerily simple. First, the AI reads the patch — the code change meant to fix a vulnerability. It compares the old, vulnerable code with the new, fixed code. By understanding what changed, the AI can reverse-engineer the flaw. It asks itself: "What did the old code do wrong that the new code now does right?"
From that insight, the AI generates a working exploit — a piece of code that triggers the vulnerability to gain unauthorized access or cause damage. The entire pipeline, from patch to exploit, took just 30 minutes. This is a speed that human attackers, who might need days or weeks to analyze a patch, cannot match.
Critically, the AI didn't just copy-paste existing exploit code. It reasoned about the underlying logic of the vulnerability and crafted a novel attack. This represents a qualitative leap. It means that the moment a vendor releases a security update, the clock doesn't tick for defenders anymore — it explodes. Attackers can now deploy AI to immediately weaponize the patch, potentially affecting millions of systems before they even get updated.
The 90-day window was built on a simple assumption: that the time between a fix being found and the public learning about it was largely safe. Researchers believed that only a small group of specialists could turn a patch into an exploit, and that took time. That assumption is now false.
With AI, the cost and skill required to weaponize a patch drop to nearly zero. Once a patch is out, anyone with access to the model and the patch files can have a working exploit in 30 minutes. The "pain" of responsible disclosure — that the public might learn of a flaw before they can patch — has been replaced by a new, terrifying reality. Now, the very act of releasing a patch can trigger an automated exploit wave.
This forces us to ask a hard question: Should vendors even release patches publicly anymore? But not patching is worse. The vulnerability remains open. The industry is caught between two impossible choices. The 90-day window, once a cornerstone of trust, is now a casualty of AI speed.
This development is a vivid example of a broader trend: AI is compressing timeframes in every domain. Tasks that once required deep human expertise are now automated in minutes. For AI itself, this signals a shift from assistive AI (suggesting ideas) to autonomous AI (executing complex, multi-step tasks like vulnerability analysis and exploit generation).
But this is not just about cybersecurity. It illustrates a fundamental principle: AI can learn from differences. AI excels at seeing patterns in change. Whether it's a patch in code, a change in financial data, or a shift in a supply chain, AI can deduce the underlying weakness and act on it. In the future, we will see AI used to rapidly reverse-engineer any kind of "fix" — be it a security update, a regulatory change, or a competitive move.
We must also expect that AI models will get better at this. The 30-minute timeframe is a starting point. Future models may do it in seconds, or even predict the exploit before the patch is released. The arms race between AI-powered offense and defense will define the next decade of AI development.
The traditional patch management cycle — test, approve, deploy over weeks — is now reckless. If a patch is weaponized in 30 minutes, any delay in applying it is an invitation to be hacked. Businesses need automated, zero-touch patching that deploys critical updates within minutes of release. This is hard in complex environments, but the alternative is far worse. Expect to see AI-driven patch agents that can automatically verify and deploy fixes without human intervention, but also with safeguards to prevent a bad patch from breaking systems.
Vendors will likely shift toward silent, staggered patching. Instead of a big public announcement with a detailed advisory, they may release fixes silently and slowly roll them out to users, so attackers don't have a clear "patch event" to exploit. This creates ethical tensions: users might not know they were vulnerable. But in a world where disclosure is a liability, silence becomes a strategy. We may also see AI-powered defense models that analyze patches internally to develop their own blocking rules before the patch is even released to the public.
Laws around vulnerability disclosure and cybercrime need updating. If an AI autonomously creates an exploit, who is responsible? The person who ran the AI? The developer of the AI? The vendor who released the patch? Clear liability frameworks are missing. Governments will need to invest in offensive AI capabilities to protect critical infrastructure, but also regulate the use of such tools to prevent AI-powered hacking at scale. Expect new laws requiring AI models to have "safety brakes" that prevent them from being used to generate exploits without authorization.
For regular people, this means that the window between a software update being available and their computer being at risk is shrinking to near zero. The old advice of "wait a few weeks to patch to see if the update is stable" is gone. You must patch immediately, or risk being compromised by an AI-generated exploit. This will drive adoption of automatic updates across all devices — from phones to smart home gadgets — and increase the pressure on manufacturers to make updates reliable and safe.
The ability of AI to turn patches into exploits in 30 minutes is not a scary story for the distant future. It is happening now. It marks the end of the era of patient, manual exploitation and the beginning of automated, hyper-fast cyberattacks. The 90-day disclosure window was a luxury we could afford when humans did the work. AI has taken that luxury away.
For businesses, the message is clear: your patching process must be faster than the AI that weaponizes patches. For society, we must accept that cybersecurity is no longer a once-a-season update — it is a real-time, always-on battle. And for AI itself, this is a stark reminder that every powerful tool can be used for good or harm. The future of AI will be defined by how we manage these dual-use risks. The speed is here. Our response must match it.