AI systems are discovering security vulnerabilities at scale, but attackers remain selective about which ones they exploit. VulnCheck tracked 1,061 vulnerabilities identified by AI in the first half of 2026 and found that only 14 resulted in confirmed attacks. That represents a 1.3 percent exploitation rate, matching the overall rate for all vulnerability types.

The data suggests AI-driven vulnerability discovery hasn't created a new attack surface. Threat actors continue targeting specific flaws rather than weaponizing every newly disclosed weakness. This aligns with known attacker behavior: they prioritize vulnerabilities offering high impact or affecting widely-deployed systems.

However, one metric shifted noticeably. The median time between vulnerability discovery and active exploitation dropped from 120 days to 80 days. Attackers are moving faster when they do decide to exploit AI-found flaws. This compressed timeline creates urgency for patch deployment.

The findings carry practical implications for security teams. The flood of AI-discovered vulnerabilities remains manageable from an exploitation perspective, but the accelerated attack window demands faster incident response. Teams cannot rely on 120-day response windows anymore.

VulnCheck's analysis separates hype from reality in the AI-security space. Vendors often tout AI vulnerability discovery as transformative. The data shows it produces volume without necessarily multiplying real-world risk. Yet the faster exploitation timeline introduces a genuine operational challenge.

The results suggest a bifurcated landscape. AI tools excel at finding flaws at scale, improving overall vulnerability visibility. Attackers, however, maintain disciplined targeting strategies. They exploit flaws strategically rather than opportunistically. Organizations deploying AI-driven security tools should view them as discovery and visibility enhancements, not as solutions to attacker behavior itself. The real bottleneck remains patch deployment speed.