The note · August 30, 2026
AI Speeds Up Security. The Last Mile Is Yours.
I left a comment on somebody else's LinkedIn post a few days ago and got a better sentence back than the one I wrote. It has been rattling around in my head since, because of what it says about who gets to help with the backlog AI is building faster than anyone can work it off.
Most security data is not allowed to leave the building it lives in. That one constraint is why more than 120 companies joined NVIDIA's open-weights security alliance this summer, and why open models matter to anyone defending a network. AI opened a wide gap between the vulnerabilities being found and the ones getting fixed. Both ends are speeding up now. What AI cannot do is install those fixes inside thousands of separate client environments, one change window at a time, which is exactly where MSPs and MSSPs already stand.

From my desk, August 30.
A few days ago I left a comment on somebody else's LinkedIn post and got a better sentence back than the one I wrote.
Chris Konrad runs global cyber at World Wide Technology. He had posted about why open models matter for defense, and one line in it stopped me cold. His words: “Defenders cannot be limited to black-box systems they cannot inspect, adapt, test or operate within their own environments.”
Here is the part of my comment that matters:
A lot of security data can't leave the building, so the model has to come to the data, and that's the practical case for open weights in the defense stack.
Chris agreed, and then said this:
For a lot of the most sensitive defensive use cases, the data cannot move so the model has to. Open weights give defenders the ability to bring capability into the environment, control it, harden it, and operate it against the data where it already lives.
I have been chewing on that last bit ever since. Everybody assumes you move the data to the model. Turn it around, move the model to the data, and a whole category of problems goes away. That matters a great deal if you sell managed services, and to explain why, I have to back up to this spring.
What a machine found in code nobody thought to check
In April, Anthropic pointed an unreleased model at a big slice of the open-source software the internet runs on. Eleven partners came along, mostly the security and infrastructure names you would expect. They called it Project Glasswing.
It found a sixteen-year-old flaw in FFmpeg, which is the software running underneath nearly every video player and streaming service you have ever used. That one had survived more than 5 million automated tests without anybody catching it. It found another in OpenBSD that had been there twenty-seven years. By late May, participants across the whole effort had turned up roughly 10,000 critical and high severity flaws in their own products, and the model found 6,202 more in the open-source projects it scanned.
Twenty-seven years is the part I cannot get past. That is a project whose whole reputation is built on people auditing the code, and the flaw just sat there the whole time.
I do not think that means the machine is smarter than the people who wrote the code. I think it means the machine never gets tired, never gets bored, and never decides it has looked at this file enough. Hunting vulnerabilities rewards stamina more than brilliance. That is good news. Better found than left sitting there.
Finding is not fixing
Then came the part that got everybody's attention. Anthropic keeps a public ledger of what it has disclosed and what has actually been fixed, and back in May it showed 1,596 findings handed to maintainers across 281 projects, with 97 of them patched.
Six percent. Finding had outrun fixing by a mile.
It is worth being clear about whose backlog that actually is, because the number invites the wrong conclusion. Those are upstream maintainers fixing their own code, in projects most of your clients have never heard of and every one of them depends on. It is not anybody's managed client environment.
Then I pulled the same ledger again before writing this. As of its August 26 update, disclosures were up to 2,300 and patched was up to 421. Six percent had become eighteen.
27 years
How long one flaw sat unnoticed in OpenBSD
5 million
Automated tests a 16-year-old FFmpeg flaw survived
6% to 18%
Glasswing findings patched, May to late August
120+
Companies in NVIDIA's open alliance, as of August 30
Part of that is a wider net. Anthropic was scanning with one model in May and several by August, so some of the jump is simply more looking.
But that does not explain the shape of it. Findings went up by less than half. Fixes went up more than four times over. That is the fixing side gaining ground.
So the easy version of this story, the one where AI got good at finding and nobody got better at fixing, is already out of date. OpenAI put its own tools on the other end of the problem in June, working with outside security firms on projects like cURL, Go, and Python. Those are running inside your clients' environments right now whether anybody has ever mentioned them to you or not.
The pileup is real. It just moved.
The last mile is somebody's building
In between a maintainer merging a fix and a mid-sized company actually running it, there is a pile of work nobody has automated, and probably nobody will.
An asset list that is never quite accurate. Change windows. A patch that takes the accounting system down at two in the morning. A client who will not accept downtime anywhere near quarter close. A compliance officer who needs the whole thing documented afterward. That work happens inside thousands of individual buildings, one at a time, and no frontier lab can reach into those buildings to do it.
Which is where you already are, if you run an MSP or an MSSP. It is also the one step that gets harder as everything around it gets faster. Finding got faster. Fixing upstream is getting faster. Installing did not, and it has more to carry every quarter.
Two alliances, four months apart
Which brings me back to Chris's post.
In July, NVIDIA launched the Open Secure AI Alliance. Same broad problem, opposite architecture: open weights and open tools, the kind a defender can download, inspect, and run themselves. Five weeks later it was past 120 member companies.
The interesting part was not that the industry split into camps. It was that the serious defenders refused to pick one. Cisco, CrowdStrike, Microsoft, Amazon, Palo Alto Networks, and the Linux Foundation all show up in both efforts, about four months apart, on opposite architectures.
I take that as need rather than indecision, and to be clear, that is my read and not something any of them has said. The closed frontier models are the ones that can find a twenty-seven-year-old flaw. Open weights are how anything like that gets near data that is not allowed to leave a building. Defend a large enterprise and you have both problems at once, so you sit in both rooms.
One more thing is worth saying out loud, since anybody who checks the roster will notice it anyway. On the roster I read on August 30, OpenAI, Anthropic, Google, and Meta were all absent from the alliance. I am not going to guess at anybody's reasons, and it may not stay true for long. What filled it up instead is the crowd that actually buys and installs this stuff: security vendors, infrastructure providers, and a long tail of smaller model labs.
Finding can happen anywhere. Running the model has to happen where the data is.
Why any of this reaches your clients
A lot of the data your clients most need analyzed is not allowed to go anywhere.
Protected health information. Credit card data. Criminal justice records under CJIS. Anything covered by a defense contract. Anything a cyber insurance policy says has to stay put. And log data, which if it ever leaked would hand somebody a map of the client's entire network.
For that data, “we will run it through a model” is not an architecture decision. It is a contract question, and the answer is often no.
A lot of security data can't leave the building, so the model has to come to the data, and that's the practical case for open weights in the defense stack.
For anyone who wants it one level down: a hosted frontier model lives behind an API, which means the data crosses your client's boundary to get processed, and your control ends at that boundary no matter what the vendor's retention policy says. Open weights turn that around. You download the model itself, run it on hardware inside the environment, and the data never moves. You give up some raw capability. In exchange you get inspection, tuning, containment, the ability to run offline, and a straight answer for the auditor.
That tradeoff is the actual decision, and there is nothing ideological about it. Vendors who make it sound ideological are usually selling one side of it.
What I would do if I ran an MSP right now
Four moves, in order.
- Write down where each client's data is allowed to go, before you evaluate a single model. Their contracts, insurance riders, and compliance frameworks already answer this. Most teams find the constraint halfway through a deployment, which is the expensive way to learn it.
- Split discovery and remediation in how you sell. Discovery is getting cheaper and more plentiful every quarter, and it will end up bundled into tools your clients already pay for. Remediation capacity is the thing nobody can conjure out of nowhere. Sell the scarce one.
- Price remediation as standing capacity, and keep per-finding records anyway. Every patch that clears upstream lands in somebody's queue eventually, and the volume upstream keeps climbing. That makes this ongoing work rather than a series of projects, which is to say it is a retainer. Keep the item-level trail regardless, because the frameworks your regulated clients live under tend to want a dated record for each item, and a capacity retainer with no evidence underneath it will not survive that conversation.
- Decide where your models are allowed to run, on purpose, and put that decision in writing. Most of you do not host models at all. You resell tools whose architecture the vendor controls, so start there: ask every security vendor where their inference runs and what leaves the client's boundary, and write the answers down. That document is the deliverable. Say it before a client's auditor asks, because I would not want to be drafting that answer under deadline.
Not one of those is a technology decision. They are positioning, pricing, and message decisions, which is exactly why they tend to sit unmade while everybody evaluates tools. Getting them made is where a Fractional CMTO seat earns its keep.
The line I keep coming back to
Chris and I were talking about model architecture. What we were actually talking about was who gets to help.
AI found the work. It is going to keep finding it, faster every quarter, in code nobody has read closely since 1999, and it is learning to write the fixes too. What it cannot do is walk into your client's building on a Tuesday night and install the fix, inside a change window somebody had to negotiate, on systems holding data that was never going to leave.
That is a good place to be standing if you sell managed services. The work is arriving where you already are.
The model has to come to the data. That is already true. Build for it.
All signal. No noise.
Frequently asked questions
What is the Open Secure AI Alliance?
It is an industry group NVIDIA launched in July 2026 to build and share open tools for securing software and AI agents. It passed 120 member organizations within about five weeks, including Microsoft, Cisco, CrowdStrike, Palo Alto Networks, IBM, Red Hat, Hugging Face, the Linux Foundation, and World Wide Technology. The point of it is open weights: models a defender can download, inspect, and run on their own hardware instead of calling out to somebody else's.
What is Project Glasswing?
Anthropic announced it in April 2026 with eleven partner organizations. It used an unreleased frontier model to hunt for vulnerabilities in widely used software. Participants reported roughly 10,000 critical and high severity flaws in their own products, and 6,202 more in the open-source projects the model scanned, including flaws that had gone unnoticed for sixteen and twenty-seven years.
Can security data be sent to a hosted AI model?
Often it can, and for plenty of work that is the right call. But protected health information, credit card data, CJIS-covered records, defense contract data, and detailed network logs are frequently restricted by contract, regulation, or a cyber insurance clause from leaving a defined boundary. When that is the case, the model has to run inside the environment instead, and open weights are what make that possible.
Are open-weight models as capable as frontier models for security work?
Not across the board, and anyone telling you otherwise is selling something. The largest closed models still lead on the hardest reasoning, which is why a closed model did the discovery work on Glasswing. Open weights win somewhere else entirely: inspection, tuning, containment, offline operation, and the ability to run where the data already is. Most real defense stacks are ending up with both.
If AI finds vulnerabilities this fast, why is so little getting patched?
Upstream, it is catching up faster than people assume. Anthropic publishes a running ledger of the Glasswing disclosures. In May it showed 1,596 findings disclosed to maintainers across 281 projects and 97 patched, about six percent. By late August the same ledger showed 2,300 disclosed across 392 projects and 421 patched, about 18 percent. OpenAI's Patch the Planet, launched in June, also put AI to work writing the patches themselves on projects including cURL, Go, and Python. The step nobody has automated is the last one: installing a released patch across thousands of separate production environments, each with its own inventory gaps, change windows, and compliance requirements.
What does this mean for an MSP or MSSP specifically?
Two things at once. The volume of known, documented, unpatched vulnerabilities in client environments is going up permanently, which is demand for remediation capacity you already sell. And the models you can actually point at client data are limited by where that data is allowed to go, which turns where you run those models into a commercial decision rather than a technical one.
Next note · In the works
More from the Signal.
Want this thinking applied to your business?
Signal Notes can sharpen the thinking. A strategy call turns it into a plan.