Work that once took experienced security researchers roughly sixty days now takes about four hours, according to a recent analysis published in CSO Online examining the collision between AI-powered vulnerability discovery and industrial patch cycles. Frontier AI models released by Anthropic and OpenAI in April 2026 can now autonomously identify exploitable flaws in production software, a capability documented by Melissa Hathaway in Cyber Defense Review. The paper warns that four decades of "field it fast and fix it later" technical debt is now coming due, and the industry should brace for a tidal wave of patches over the next twelve to twenty-four months rather than the next decade.
At least 40 of the largest software and hardware vendors already have access to these models, the analysis notes. Anthropic's Mythos reportedly surfaced critical flaws in 99 percent of widely used operating systems and browsers, while the Chinese 360 Digital Security Group's AI discovery agent has already uncovered close to a thousand previously unknown vulnerabilities. In enterprise IT, the remediation convention Hathaway cites — seven days for actively exploited critical flaws, thirty for high severity — is ambitious but achievable. In operational technology, that convention is structurally impossible: a continuous process does not pause because a CVE arrived, and the next scheduled window may be a quarterly turnaround or an annual shutdown planned eighteen months ago.
The gap is not cultural but physical, economic and contractual, the report states. A patch that reboots a controller can trip a running process; on or near a safety instrumented system, an unqualified change is itself a hazard, not a mitigation. Most industrial components may only be updated with firmware and patches the OEM has validated against the specific product line — applying an unapproved update can void warranties, support contracts and certifications. That qualification takes weeks to months, and the clock only starts once the vendor has processed the upstream fix. Hathaway explicitly names manufacturing and healthcare as sectors running unsupported products, and the honest, auditable position for a large share of the OT estate is therefore not "patched within SLA" but documented containment with compensating controls, monitoring and a retirement date.
The models that find a flaw can develop a working attack path within hours of disclosure, and the capability is not confined to one bloc — there is no geographic sanctuary and no sectoral one, the analysis warns. OT networks, with their long-lived and rarely patched assets, are precisely where unpatched time accumulates. When AI-assisted disclosure pushes hundreds of relevant advisories into an installed base per quarter, "critical first" stops being a sort key, because too much is critical. The report recommends triage logic built on three questions: Is there exploitation evidence — a KEV listing, a rising EPSS score, an OEM advisory referencing active abuse? Is the asset actually exposed — reachable from the IT network or the internet, or buried three zones deep behind enforced conduits? And what is the consequence — what does this component do to the process, and to safety, if it misbehaves?
The report urges operators to interrogate their OEMs and system integrators now: how do they ingest AI-discovered findings, what patch volume and cadence do they expect for your installed base, and what are their qualification timelines? Europe adds leverage here: on September 11, the Cyber Resilience Act's first hard obligation takes effect — manufacturers must report actively exploited vulnerabilities through ENISA's new Single Reporting Platform, with an early warning within 24 hours and a fuller notification within 72, and the duty covers products already on the market, not only new ones. The report recommends pre-negotiating emergency windows with operations before you need them, including written criteria for when a vulnerability justifies unplanned downtime. Discovery has permanently accelerated; the disclosure pipeline is industrializing; the only variable still under an operator's control is the readiness of the remediation machine. In OT, that machine is built from change management, not scripts. The window between a flaw's disclosure and its exploitation used to be someone else's problem — the vendor's, the researcher's, the policymaker's. As of this year, it is an operations problem. The industrial control layer has become the bottleneck in a security model designed for systems that reboot in seconds, and every unpatched interval is now a tactical decision with strategic liability.

