Automation, AI agents or people? Sorting out who handles each security finding
Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today.

The respondents are senior people, most of them at companies with 10,000 or more employees, and their worries center on what happens after a scanner flags something. Someone has to decide whether the flaw matters, find out who owns it, and get the fix through teams that run on different tools and release schedules. Each delay in that chain leaves a known flaw open longer. Verizon’s 2026 Data Breach Investigations Report puts the median time to fully resolve a critical vulnerability at 43 days.
AI is adding to the pile
The pressure comes from both directions. AI tools let developers write and change software faster, and AI-assisted scanning turns up more weaknesses. Forty percent of respondents picked the amount of AI-generated code waiting for human review as their significant software-security challenge. AI-generated code is not inherently insecure, but there is more of it than human reviewers can keep up with.
That 40% comes with a catch. Each respondent picked one answer from a short list, so the figure shows that AI code review beat the other options for those people. It says nothing about how the remaining 60% rate the problem.
Who handles which finding
The survey’s second-largest share, 44%, named a tiered strategy for AI-assisted vulnerability discovery as the biggest transformation need.
“Automation should handle deterministic work: findings, remediations, and mitigations that are repeatable, low risk, and well understood,” Rob Chapman, a principal solutions engineer at ArmorCode, told Help Net Security. “Most organizations already have some degree of this in place. These findings fit well into workflows built on mature processes such as normalization, enrichment, ownership routing, ticket management, SLA management, and rescan verification.”
The middle layer belongs to AI agents, software that can work through a multistep task with limited supervision.
“Agents work well where deeper investigation and reasoning are needed. They can assess signals for reachability and exploitability, identify correlated findings, and surface potential attack paths,” Chapman said. “Because this work involves judgment calls, it needs strong guardrails for auditability and review.”
“Humans own decisions and their consequences, including risk acceptance and exceptions. The goal is not to remove people from the loop, but to reserve their limited time and attention for decisions that require good judgment and accountability,” he said.
He added one more step: “Ideally, this is a layered approach in which findings that reach humans are reviewed for opportunities to push similar work back down the stack.”
Alerts that don’t say enough
Ask these leaders what keeps them up at night, and the top pick is a flood of low-context alerts. These are warnings that flag a weakness without saying whether anyone can reach the affected system, whether it can realistically be exploited, which business service depends on it, or who should deal with it.
A team with more alerts than it can sort, and too little information on each one, has a volume problem and a context problem at once.
Too many tools, too many handoffs
Respondents’ leading goal was better remediation across security and development teams, and every option on that question involved acting on findings. You can see why when you trace a finding. It might start in one scanner, need context from several other systems, get prioritized by security, and land on a developer, a cloud engineer or an outside vendor. Each step that runs in a separate workflow costs context and time.
Asked how a security leader should decide which tools to merge and which to keep connected through a shared layer, Chapman said:
“I’d consolidate where tools overlap in function and produce undifferentiated findings. I’d keep tools that offer significant depth or unique coverage, and connect the ones that pass this test through the common layer. The questions to ask of each tool is: Does it add coverage nothing else does? Is its signal quality high? Can it integrate into my larger data fabric? Do the teams who use it trust it?”
What to show the board
“The first metric is time to remediate meaningful exploitable and exposed systems. Leaders want to know that we can identify these risks and that we are getting better at managing them over time,” Chapman said.
“Leaders also want to know where the challenges are within the business,” he said. “Organizations rarely have a single, consolidated risk surface. They are a collection of teams, assets, products, and business units that each contribute to overall exposure. Leaders need visibility into where support is needed, where change is happening, and where the potential hot spots are across the organization.”

Webinar: Closing the accountability gap in AI-assisted delivery