Like a magician performing a sleight of hand, the cybersecurity industry may be becoming fixated on the hand it can see while missing what is happening elsewhere on the stage. I call it the Great AI Source Code Vulnerability Distraction.
Today, that visible hand is source code vulnerability discovery. Frontier AI models are astonishingly effective at finding defects at machine speed and the industry is rightly captivated by the prospect. Yet while security teams celebrate ever larger vulnerability reductions, a more consequential risk may be emerging in plain sight. The same AI systems that can analyse code can also reason across workflows, policies, incentives, exceptions and business processes. In doing so, they may reveal pathways to compromise that contain no software vulnerability at all. The danger is that we become so distracted by the vulnerabilities AI can find in code that we overlook the business logic weaknesses AI is learning to expose everywhere else.
Every conference presentation now seems to feature a graph showing how many SQL injections, hardcoded secrets or authentication flaws an AI can uncover before the speaker has finished their coffee. Investors are impressed. Boards are reassured. Security teams are handed ever larger scanning reports.
Unfortunately, there is a small problem, attackers do not particularly care whether they compromise your organisation through a critical vulnerability or by simply exploiting the way your business actually works.
While the industry is busy counting CVEs, frontier models are becoming increasingly capable of understanding workflows, policies, incentives, exceptions, supplier relationships and operational processes. In other words, they are starting to understand organisations.
A model may discover that no software defect exists whatsoever. Instead, it may identify that refunds can be chained across multiple systems, approval thresholds can be bypassed through transaction splitting, support teams can be manipulated into granting elevated access or that several perfectly legitimate business processes combine to produce an outcome nobody intended. No exploit. No malware. No vulnerability. Just logic.
This creates an awkward possibility. The security industry may spend the next few years proudly reporting that critical vulnerabilities have fallen by 80%, while fraud, abuse and operational compromise continue to rise and go exponential.
Perhaps the uncomfortable truth is that source code vulnerabilities were never the hardest problem. They were simply the easiest to measure. As AI learns to reason across entire organisations, the real question is no longer whether your code is secure. It is whether your business makes sense when examined by something far more patient, consistent and analytical than the humans who designed it.
Posted on July 7, 2026
0