Council Post: The New Economics Of Software Security: Discovery Is Cheap; Response Isn't
Aaron Mitchell is CEO of HeroDevs, a company that provides Never-Ending Support for end-of-life open-source software.

getty
The recently released "Open Weights and American AI Leadership" letter has reignited the debate over whether increasingly capable open-weight AI models should remain broadly accessible and how they should be governed. But the real story isn't the models themselves. It's what they reveal about how AI is changing the economics of software security.
For years, software security operated on an imperfect but workable equilibrium. The pace of vulnerability discovery generally allowed those responsible for maintaining software time to investigate reports, validate findings, develop fixes and coordinate responsible disclosure. It wasn't especially efficient, but it was stable enough to keep the lights on for critical software applications.
That equilibrium is changing.
AI is now making it possible to identify vulnerabilities faster than many organizations can realistically absorb them, creating a growing gap between how quickly software flaws can be discovered and how quickly they can be understood, prioritized and remediated. That's the real shift, and it's one the industry is only beginning to grapple with.
The Bottleneck Has Moved
Open source is foundational to enterprise software. With 98% of commercial codebases containing open-source components, and open source making up between 70% and 90% of all the code in modern software, resilience increasingly depends on whether the ecosystem can keep pace with AI-driven vulnerability discovery.
That shift is changing the economics of software security. AI makes vulnerability discovery faster and more accessible, but it doesn't reduce the effort required to secure and maintain the software enterprises depend on.
Finding a vulnerability is only the beginning. Every finding still has to be validated, prioritized, remediated, tested and safely deployed into production. Those responsibilities don't disappear simply because discovery becomes faster.
As these models become more capable, they can generate a growing volume of findings that still require investigation. Much of that work falls to maintainers who are already balancing issue triage, feature development, release management and community support—in many cases alongside full-time jobs. The result is a widening gap between what can be discovered and what can realistically be fixed.
Enterprise security teams already struggle to manage increasingly complex software portfolios. As AI accelerates software development, every new dependency becomes a long-term maintenance obligation. AI is only lowering the cost of creating software, not the cost of owning it. Without greater investment in software maintenance, organizations risk accumulating technical debt faster than they can reduce software risk.
Investing In Software Resilience
Open source has become critical infrastructure. The software that powers banks, hospitals, governments and enterprise systems often depends on open-source projects maintained by relatively small communities. As AI makes it easier to identify vulnerabilities at scale, those communities face growing pressure to keep pace.
That isn't a failure of open source. It's a recognition that enterprise dependence has outgrown the support model many of these projects were built around. Meeting that challenge requires shared responsibility across the software ecosystem, from maintainers and enterprises to commercial support providers and governments. That recognition is beginning to emerge across the industry. Recent initiatives from IBM and the Linux Foundation reinforce the idea that discovering vulnerabilities is only part of the software security challenge.
As governments, regulators and enterprises continue to raise expectations around software accountability, the objective shouldn't simply be identifying more vulnerabilities or satisfying more requirements. It should be creating stronger incentives for continuous software maintenance, life cycle ownership and secure modernization.
Knowing what software you're running is essential, but it's only half the equation. Organizations also need a sustainable strategy for keeping critical software secure throughout its operational life cycle, including after community support ends. In the AI era, resilience won't be defined solely by visibility into software risk. It will be defined by who is accountable for managing that risk over time.
What Happens Next
AI will continue accelerating vulnerability discovery. That's good news for defenders, but it also changes where the industry needs to invest: strengthening the long-term maintenance capacity needed to turn vulnerability discovery into meaningful security outcomes.
Unless long-term software maintenance becomes a higher priority, organizations will continue to uncover risks faster than they can address them. As AI reduces the barriers to building software, long-term stewardship will become an increasingly important measure of enterprise resilience.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?