METR Study: AI Is Sharply Accelerating Cyber Vulnerability Discovery but Shows Uneven Impact Across Science
Summary
- • METR research finds AI dramatically accelerated cyber vulnerability discovery in 2026, with sharp increases across cURL, OpenSSL, Firefox, Microsoft, and aggregate vulnerability databases
- • Math research shows a likely acceleration — arXiv submissions doubled in some areas and three major open problems were solved with AI in 2026
- • Algorithmic optimization research shows no measurable acceleration attributable to AI
- • Actively exploited vulnerability databases show far lower growth than known-vulnerability databases, suggesting AI finds bugs faster than attackers can operationalize them
Details
METR study measuring AI's real-world discovery impact
Analysis using public time-series data across multiple domains to detect slope changes in discovery rates, with January 2026 as a potential breakpoint where AI's effects may first become measurable
Cyber vulnerabilities: sharp acceleration in 2026 vs. 2025
Reported vulnerabilities for cURL, OpenSSL, Firefox, and Microsoft rose dramatically in 2026; aggregate databases US NVD and OSV show similar spikes, with AI credited for most extra 2026 disclosures on cURL and OpenSSL
Higher-severity bugs: lower but still present acceleration
Higher-severity vulnerability categories show less acceleration than total counts, but acceleration is still present across all severity tiers — the most dangerous bugs are being found faster too
Exploited vs. known vulnerability gap is widening
Databases tracking actively exploited vulnerabilities (CISA KEV, Vulncheck KEV) show significantly lower year-over-year growth than known-vulnerability databases — AI is discovering bugs far faster than attackers can exploit them, but this asymmetry will narrow over time
Mathematics: likely acceleration, hard to quantify
arXiv submissions doubled in some areas in under 12 months; three major open problems solved with AI in 2026 — the Jacobian conjecture (Smale's list), Problem 44 from Green's list (the halving sieve), and the sofic half of Green's Problem 100
Optimization discovery: no clear acceleration detected
No dramatic or measurable increase in the rate of algorithmic optimization discoveries attributable to AI was found, suggesting AI has not yet meaningfully accelerated this more exploratory research domain
Study data collected and analyzed by AI agents
All data collection and analysis for the study was itself performed by AI agents with human auditing; authors note mistakes likely remain, have published source material in a public repository, and plan to keep updating the data
Import AI / METR; August 2026
What This Means
The METR study is one of the first systematic attempts to empirically measure AI's real-world impact on discovery rates across scientific and technical domains. The sharp acceleration in cybersecurity vulnerability disclosure is the most concrete and consequential finding — AI is dramatically expanding the known attack surface of software, forcing security teams and vendors to triage and patch a sharply higher volume of disclosures. The gap between known and exploited vulnerabilities provides a temporary buffer, but it will narrow as attackers adopt the same AI-powered discovery tools. The uneven results across domains — strong in vulnerability finding, modest in mathematics, none in optimization — have direct implications for how organizations prioritize AI investment in research and security programs.
