Research · curated 7 Aug 2026
AI-Generated Patches Fail Half the Time
First reported 1password.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Teams increasingly relying on LLMs to auto-generate security fixes risk deploying brittle or bypassable patches that can introduce fresh vulnerabilities, underscoring the need for human review of AI remediation output.
A 1Password Off-By-1 research team study of more than 6,000 AI-generated patches (using OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8) found only about 46% actually solved the underlying vulnerability, with many introducing new bugs, breaking other functionality, or remaining bypassable. The researchers note that AI systems appear better at exploiting flaws than patching them, and that patch success goes negative for novel vulnerabilities not in the training set.