Google has built an artificial intelligence system capable of discovering and fixing software vulnerabilities on its own, and the company has decided the tool is too powerful to release publicly.
AI Security · Frontier Capability
Google Built an AI That Finds & Fixes Bugs by Itself — Then Decided It's Too Dangerous to Release
An autonomous system, tested as "Gemini 3.5 Flash Cyber," reportedly surfaced more unknown vulnerabilities than rival tools — and in one case wrote a working exploit that slipped past standard defenses. The company is keeping it internal.
Auto
End-to-end: finds the flaw and writes the patch — no human in the loop
1
Working exploit written that reportedly evaded standard defenses
0
Public release — kept internal on dual-use risk grounds
The Dual-Use Problem
One model. Two very different hands.
DEFENDERS
Detect flaw
Auto-patch
Close gap first
Shifts balance toward defense
vs
ATTACKERS
Find flaw
Weaponize
Exploit fast
Lower barrier
Same skills, offensive use
The gap between defensive tooling and attacker capability collapses when a single model can do both .
The Case For
Automated bug hunting run at scale could let defenders close vulnerabilities before attackers reach them — a long-argued advantage for security teams.
The Caution
The results come from internal testing only, with no published architecture and no independent verification — so claims of superior performance can't yet be scrutinized.
Why it matters: As AI systems capable of end-to-end vulnerability analysis mature, the choices developers make on disclosure, access controls, and release will decide how fast these powers reach defenders — and adversaries. For now, Google treats autonomous exploit generation as a line that warrants caution over open distribution.
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…