What changed technically
On 14 August 2026, Perkins Coie documented a precise operational pattern. Agentic AI models have flooded corporate vulnerability disclosure programs.
The phenomenon affects companies of every size and sector.
WIRED reported the same dynamic in a recent article. A researcher quoted estimated a volume of reports triple that of the previous year, as reported by Perkins Coie. The same researcher anticipates a wave of low- and medium-difficulty reports in the near term.
The quantitative figure must be read precisely. A tripling of reports over twelve months compresses every team's response time. Response capacity stays constant while input grows.
This is the technical signal that matters.
The mechanism of the economic attack
The operational flow stays constant. An individual contacts one or more people inside the company. They claim to have found a flaw, for example sensitive data reachable from the public network.
They provide partial proof. Then they introduce the economic lever: a public blog, a remediation request, a demand for payment.
The interaction often follows a recognizable sequence. The researcher asks to speak with an executive. They raise the topic of payment in polite terms.
Responsible disclosure remains a legitimate practice. Many companies run bug bounty programs precisely to channel this work into clear rules.
The root condition
The root condition that both dynamics share is economic. The cost of entry and the expertise required for security research have collapsed.
An AI agent generates dozens of reports at the marginal cost of a query. Average quality drops. Volume explodes.
The pattern repeats a known trajectory. Every time a tool lowers the technical barrier, the volume of output outpaces verification capacity. Web apps in the 2000s went through the same curve.
Those presenting themselves as researchers now include less professional profiles than the established predecessors. The economic incentive attracts opportunistic behavior.
Companies with and without a program
Companies with a bug bounty program face a throughput problem. The volume and speed of disclosures increase beyond the capacity of internal processes.
The incoming flow mixes two categories. Many low-value reports. A few high-impact vulnerabilities hidden inside the noise.
Companies without a program face the greatest risk. A researcher contacts them, asks for payment, and finds no rules of engagement in place.
The difference between the two categories is procedural. An existing program defines authorized methods, contact channels, and response expectations. Its absence leaves the company exposed to the first hostile request.
The legal and reputational risk
The researcher's leverage rests on two threats. The first is public exposure of the flaw via a blog. The second is direct economic pressure.
A company without rules of engagement faces this pressure in real time. The decision to pay or refuse happens under the threat of publication.
This scenario favors those who established clear boundaries in advance. A published program defines what constitutes authorized research and what constitutes extortion.
Why volume turns an advantage into a trap
Manual triage of this volume becomes unsustainable. Every report requires validation, reproduction, and classification.
A process calibrated to 2024 volume accumulates operational technical debt. The queue grows. Real vulnerabilities stay buried longer, and the exposure window widens.
The hidden cost is the attention time of senior engineers. Every hour spent triaging noise is an hour taken from remediation work. This trade-off worsens with rising volume.
This is where an advantage, namely free external input, converts into a trap. The governance of the flow decides the outcome.
How to calibrate automated triage
The technical response to automated volume is automated filtering. A deduplication system reduces the redundant reports generated by agents.
Severity classification precedes human intervention. Independent validation confirms reproducibility before escalation. This preserves engineers' time for real vulnerabilities.
A circuit of this kind works as a circuit breaker. It blocks the cascade of low-value reports before it saturates the triage queue.
Continuous monitoring of the report rate provides an early indicator. A sudden spike signals an automated campaign in progress.
Three questions for the enterprise AI team
Three questions guide the review for any enterprise AI team. Each has immediate operational scope.
- What is the maximum volume of reports the internal process can handle in a week?
- What published rules of engagement define authorized research?
- What deduplication system filters agent-generated reports?
The quality of the answers measures the maturity of the program. A prepared team responds with documented procedures. An unprepared team improvises under pressure.
Every missing answer indicates a process calibrated to a report volume that is now obsolete. The review comes before next quarter.
Procurement decisions for the next cycle
The decisions for CTOs and Heads of Engineering in the next planning cycle concern automated triage. The build-versus-buy choice becomes concrete.
An externally managed disclosure platform outsources the first level of filtering. An internal system keeps control of sensitive data. The cost of each option depends on expected volume.
The economic calculation changes with the documented trend. A triage budget sized to past volume is now insufficient. The revision of the vendor contract reflects this reality.
The CFO assesses this as recurring operational spend, calibrated to the tripled trend. The Technology Procurement Committee renegotiates contracts with bug bounty vendors now.
The decisive factor remains the ability to distinguish signal from noise at scale. Those who automate triage with independent validation maintain fault tolerance.
Those who leave the process manual accumulate risk with every cycle.
The position
The security posture of AI systems remains 2-3 years behind the maturity of security infrastructure. Companies deploy agentic capabilities in production before developing process hardening practices. This wave of automated disclosures repeats the mistake seen with web apps in the 2000s.
The structural question remains the same for every security architecture. Is this managed disclosure capability a trap or a competitive advantage?
The answer depends on the governance of the flow, the speed of validation, and the clarity of the rules of engagement. Companies that invest now convert volume into intelligence. The others accumulate queue and risk.
The next planning cycle decides the outcome. More analysis on the risk of agentic systems is available on our blog.
This article was written by an AI editorial author with human oversight, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by LEON
Sources
- Perkins Coie (ashurstperkinscoie.com)
- Elastic Security Labs (elastic.co)
- CSO Online (csoonline.com)
- The Register (theregister.com)