
Researchers at 1Password tested AI-generated security patches from ChatGPT and Claude and found that only 26 percent fully fixed vulnerabilities without side effects, with nearly half failing to remediate flaws at all.
The authors argue that autonomous, human-unsupervised patching poses significant long-term risks because the cognitive load of reviewing mostly incorrect patches may cost more effort than having engineers patch vulnerabilities directly.
What happened
Researchers at 1Password's Off-by-1 Labs tested security patches generated by ChatGPT 5.5 and Claude Opus 4.8 across six recently disclosed CVEs, producing 6,080 patches total. Only 26.0 percent fully resolved the vulnerability without changing application behavior; 20.1 percent fixed the issue but altered how the application works, 2.3 percent introduced new security issues, 49.3 percent failed to fix at least one existing exploit path, and 2.2 percent both failed to fix the vulnerability and opened a new one.
Why it matters
The authors conclude that the expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin. Even successful patches often prove fragile—more than a third in the clean or behavior-changing categories didn't address the underlying problem. While a single successful patch costs just $6.74 on average, human review overhead may exceed the cost of engineers patching vulnerabilities themselves using standard LLM-assisted techniques.
What to watch
The success rate for LLM patches depends heavily on initial guidance—jumping to 65.0 percent with correct guidance but plummeting to 15.2 percent with incorrect guidance. The researchers have released a patch evaluation harness called FLAWED that organizations can use to test their own LLM-assisted security fixes.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Israeli startup DataAgent Ltd
SK Hynix presented a custom HBM concept at SEMICON Taiwan 2026, where compute functions are placed in the base…

The U.S. Department of Defense announced on August 31 that it has deployed ChatGPT Mil, a customized version o…

Nvidia reported earnings that were both remarkable and boring, reflecting its focus on avoiding a consolidated…

Anthropic has agreed to a $35bn cloud-computing contract with Lambda, a Nvidia-backed cloud provider

The Supreme Court of Japan has included about ¥60 million in its fiscal 2027 budget request for AI-related exp…
