When it comes to keeping up with AI-powered updates, we need to move from human speed to machine speed

AI has turned vulnerability discovery into a machine-speed arms race, says IT manager Michael Dear. Our human-speed patching model simply can’t keep up

I recently wrote about what I thought would occur for the rest of the year in relation to Anthropic’s AI frontier model Mythos. You may remember it was considered so dangerous that the US government declared no one could use it outside America’s borders.

We have since seen a complete change of pace in patches, both in numbers and timings. It used to be that the big players dumped a few dozen patches per month. We, as an IT team, would sort through them and apply them. Now, Google and Adobe have moved to weekly or bi-weekly patching. Others, notably Microsoft, are dropping a thousand patches a month.

The numbers are staggering and there is no way that IT teams are going to be able to do everything. Most organisations should have the ability by now to auto patch Windows, along with the most important server and desktop apps, so those aren’t the issue. It’s the less critical updates. Even if you do a gradual rollout to test these, there will be times when the patches aren’t applied and the vulnerabilities are being exploited.

I know it sounds like this is a just a wave that us IT types should ride and get on with it, but it does raise some interesting questions. Starting with this.

Is this a wave or the new normal?

The best-case scenario is that this is a wave of patches that’s back filling years of problems that have been there all this time. So they’re finally being fixed and the same AI that’s finding these problems will help developers write new, secure code. Or the AI that’s writing future code will know about these issues and avoid them. 

In this scenario, the sun-lit uplands are almost in view. Perfect, secure code is just around that corner. That is a wave.

The new normal isn’t so rosy. Take Firefox. When it fixed the bugs Mythos found, it asked Mythos to check the code again. No surprise here: it found more bugs, ones it had missed the first time around not one introduced in the fixes. 

This suggests we’re entering an iterative process, where developers are always finding bugs in code. History suggests there is no such thing as perfect code, and whilst the torrent of bugs that we’re patching now is a high water mark, we’re not going back to the previous levels.

As you may be able to tell, I believe we’ve entered into the new normal.

AI’s machine speed vs human’s human speed

AI works fast. I’m going to call it machine speed, while we humans work at human speed.

The trouble is that machine speed is so much faster. And if patches are coming at machine speed and applied at human speed, then the pile just gets bigger and bigger, even if the speed of patches slows down slightly. 

The immediate solution to the human speed problem is to risk assess and apply patches in the order of severity (however you define that). You must also accept that you’ll never apply them all.

But there’s another approach, one where you move patching to machine speed. This means the entire existing patch system must be rethought, because AI will need to stand up a test system, test the patch and check nothing breaks. And then apply it to everything. 

That’s human-like behaviour, but it takes a lot of trust and contains the ability for AI to take down potentially everything at machine speed when it makes a mistake. At least when mistakes happen at human speed, there’s someone on the team who can think “oops that’s bad” and knows how to fix it.

At machine speed, the human is in a far tougher situation. To fix the problem, they start from scratch and must work out what actually went wrong. The problem may actually take longer to fix, at greater cost, even if you’re fixing more problems overall. 

It will be a balancing act, but whatever happens will mean paying more than you are currently.

AI security patches: The hidden problem

I want to discuss one final thing. While laptops, PCs, tablets and servers are all important, there is a class of machines that few users think about. They normally exist locked away in comms cabinets and blink little lights, and they run the network that everybody uses.

These are the network devices. The sensors, switches and routers that glue everything together – and that, historically speaking, aren’t patched quickly. If patches happen at all, there’s applied when no one is around late at night or weekends.

As someone who has been there and done that, I can tell you that careful consideration is made before anything is done to them. When they break, everyone knows about it. 

Serious IT pros look at patches for these devices, look at the vulnerability, and then measure what it promises against what is running. If the rewards don’t add up, they may ignore the patch rather than risk applying the latest patch just because it’s there.

All of which happens at very slow human speed and is mostly manual.

What can be done? Devices that aren’t presently in the auto patch systems will have to be brought into them and then moved into machine-speed patching as well. But as network devices can’t be made in a virtual machine and tested easily, you may actually need a separate, redundant network to test on. Which is expensive as these types of devices are expensive.

Outside of the corporate world

So far I’ve been talking about business devices, but home devices will need to be patched just as fast. And the problems are just as big. We’ll need a new breed of unmanaged home equipment – like your internet wireless box – that can phone home to a secure location to patch themselves.

That should help keep the internet safe for everyone, but if that has issues who is going to deal with half a million routers bricking themselves?

The UK government recently announced its Cyber Shield initiative, essentially a UK-wide cyber defence system. If it can make this work I promise not to call it Skynet or VIKI, but it may turn out that we need something like them. Ramping up to machine speed is going to be expensive, and it needs to happen at scale.

About The Author

michael dear
Michael Dear

Michael has worked for more than 20 years running IT departments, mainly for small to medium insurance firms. His primary interest is focused on security and compliance.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.