AI has collapsed the cost of finding vulnerabilities to almost nothing. What used to take a researcher years of expertise and expensive tooling now takes a junior developer with an LLM and a fuzzer. The researcher pool is not growing from thousands to tens of thousands. It is going from thousands to millions.
The numbers already moved. 2024 saw about 40,000 published CVEs, a 38% jump over 2023, the largest single-year increase in the history of the program. Projections put 2026 near 55,000 and 2028 past 125,000.
Finding vulnerabilities is a solved problem. It is solved to the point of drowning. The real problem is telling which ones matter.
A modern device already carries millions of known vulnerabilities across its stack: firmware, embedded software, a web app, a mobile app, and the networks between them. Almost none are exploitable in that specific product. A few could hurt a patient. The job was never to list them. The job is to separate the few from the many, and in a regulated product you cannot just assert that separation. You have to evidence it.
AI makes this worse in a specific way. Variant finders take one published CVE and locate the same pattern across every related library. Exploit generators turn a description into a working PoC. Lower-quality disclosures arrive at higher volume, each one still requiring an evidenced disposition under CRA and postmarket timelines.
A traditional penetration test is a payroll problem. One or two testers, two to four weeks, a scope trimmed until it fits the invoice. A human spends hours coaxing a single interface to misbehave, and every one of those hours is billed. When attention is priced by the hour, coverage is decided by the budget, not by the attack surface. That is how the industry landed on the annual pentest: not because devices change once a year, but because that is what the labor market allows.
AI discovery has no such bound. It has not been proven smarter than a strong human researcher, and it does not need to be. It works in minutes, runs around the clock, and the marginal attempt costs close to nothing. A tester who is merely as good as a human, at a fraction of the cost and a thousand times the frequency, does not tie the game. It changes the sport.
Play that forward. Discovery volume grows by orders of magnitude: from researchers, from variant finders, from anyone with a model and a target. And that volume breaks the next process in line, triage. Manually triaging machine-generated findings repeats the exact economic mistake that broke pentesting: human hours spent on output machines produce for free. At sufficient volume it is not just unaffordable. It is not worth doing at all.
The only response that scales is to stop touching findings by hand. Automate the context: which component the finding lives in, which interface reaches it, whether the graph connects it to anything a patient depends on. Automate the attempted verification: try it against the device, capture what executed and what could not, and move on. That is the design behind Autonomous Testing, where the agentic harness generates and runs the attempts continuously, and Exploitability Verification, where every claim is settled on the running product instead of in a triage meeting.
AI splits vulnerability work into two layers. The first is discovery, now effectively free. The second is contextual verification: determining which findings are actually exploitable against a specific device rather than theoretically present in it. The second layer is where the value moved, and it is the layer almost nobody has automated.
That is what we do. We build a digital twin of the device, run discovery continuously, and verify exploitability against the real attack surface, including on real hardware through TestLink™. What is reachable is exposure. What is not is evidence. Developers see the handful that need a fix. Everything else is dismissed with the reasoning captured for regulatory review.
The avalanche is real. The thing that matters is knowing which flakes are the avalanche.
Start with one device. We build the twin from documentation your quality system already produces, run AI discovery remotely, and show you the graph: the handful to fix, and the evidence for everything else.
One issue a month on AI, exploitability, and FDA cybersecurity review. No spam, unsubscribe anytime.