AI-found, AI-fixed vulnerabilities via Windows updates a huge problem for all

Microsoft is facing an unprecedented challenge with its operating systems – is this a war it can possibly win?


Windows updates
AI-generated malicious code looking for operating system vulnerabilities is easier than ever to put together, so Microsoft can only fight back with AI-coded patches released as Windows updates. AI vs AI, but… with your PC being their battlefield. Great. (Image composition: The Point Online)


It’s the kind of thing that should not be happening… only it is happening right now and there’s apparently nothing anyone can do about it: as yours truly is writing these lines, no less than four of his home PCs (including his daily driver) are downloading and installing the Patch Tuesday Windows 11 update for September 2026. The problem: it’s taking too long for comfort, as every single minute now feels like an hour of nervously waiting for something to break. The reason: why, AI of course! What else could it be?

Context first: Microsoft has an embarrassingly spotty record when it comes to operating system updates, having released more than a few Windows 10/Windows 11 ones that literally broke perfectly working PCs or deleted user files. Yours truly, having had his daily driver machine enter an unbootable state due to a problematic Windows update twice in the past, knows all too well how nerve-wracking the experience can be. So he’s not at all ashamed to admit that he’s always worried when installing mandatory Windows updates, as are lots of other professionals whose work depends on specific computers and local apps on a daily basis.

In the age of AI, though, Windows updates will be more important than ever in terms of system security – in a sense that’s both positive and negative. You see, the most powerful LLMs have become extremely effective in identifying weaknesses in operating system code – weaknesses that can be easily exploited by hackers. So companies like Microsoft have no other option but to also use AI models in order to either find the same vulnerabilities first or fix the publicly documented ones before hackers make use of them.

Windows updates
Windows 10 is still being used by over 30% of the Windows total user base, so it is also a target for AI-generated malicious code. Microsoft not really eager to commit a lot of resources to it makes things even worse for millions of consumers. (Image: Microsoft)


As The Verge‘s Tom Warren claims in his latest Notepad newsletter:

Microsoft typically patches around 100 flaws every month, but in June it set a new record of around 200 fixes. July’s patch Tuesday was even bigger, with Microsoft patching at least 570 security holes, almost triple the number of June’s record-breaking release. Microsoft engineers had a chance to catch their breath a bit in August when they plugged nearly 400 security vulnerabilities […] but September’s patch Tuesday will set a new record, with more than 650 security fixes for Windows alone. That’s six times the number that usually got patched before the AI models arrived.

Dan Goodin over at Ars Technica paints an even darker picture of this month’s Windows patch release while illustrating how things are going throughout 2026:

By security researcher Duston Childs’s count, this Tuesday’s release patches 972 vulnerabilities – 997 when counting the porting of fixes for the Chromium browser incorporated into Edge. Of the new vulnerabilities, 112 of them are rated “critical”, with the remainder carrying the “important” designation. Microsoft has fixed 2760 vulnerabilities already this year, more than double the number from last year. At this rate, Microsoft will complete 2026 having fixed more bugs than through all of 2023, 2024 and 2025 combined.

Summing it all up: AI models are used daily to find and exploit weaknesses in the live, active code of the two most widely-used computer operating systems in the world (that’s still Windows 11 and Windows 10), while other AI models are used to fix the same or other weaknesses, while both AI models are in a race against time and each other. So now the stability and safe use of almost 1.5 billion consumer devices pretty much depends on AI-generated code, as it is hard to imagine Microsoft’s software engineers having the time to write the necessary patching code by hand – or extensively test it before release, to be honest – when each one of those updates brings several hundred different fixes to the Windows code base every single month.

Windows updates
Security was never Windows 11’s strong suite anyway, but AI-powered threats focusing on it may be the last straw for people who were already fed up with it in terms of performance and user privacy. Microsoft may be fighting a losing battle here. (Image composition: The Point Online)


The thought is just… scary. If Microsoft delivered so many sloppy, untested Windows updates in the past – when Windows was not an operating system under attack by AI agents specifically looking for security holes they can exploit – what are we to expect now? Are we to believe that Microsoft’s own AI agents will flawlessly write the necessary fixing code for literally thousands of vulnerabilities every year, all in a timely fashion? Are we also to trust that these AI agents will do such a remarkably surgical job, fixing so many security issues every month without ever causing any other issues to the rest of the operating system in the process?

It’s fair to say that, given Microsoft’s track record and the breakneck speed at which AI coding is currently moving, this does not look good for Windows – especially with Windows 10 (an OS Microsoft would rather leave behind but is forced to support until October 2027) still commanding over 30% of all Windows machines. Whatever the mix of Windows 10/11 turns out to be over the next few years, one thing is glaringly obvious: both operating systems represent an attack surface that’s just too attractive to hackers and too difficult for Microsoft to defend in the age of AI. This “cat and mouse” situation also depends on how quickly Microsoft’s security patches are actually applied (especially by businesses), which makes this even more of a complicated issue.

It’s just a matter of time, then, before either attacking AI finds a devastating Windows exploit or defending AI writes code that breaks Windows in other places because of insufficient testing. That’s one more reason, among many others, for consumers to leave Windows behind and migrate either to macOS or Linux. Those operating systems will also become targets of AI-generated malicious code at some point, yes, if they haven’t already. For the foreseeable future, though, they are far safer, both as smaller targets and as operating systems based on better architecture. Kind of ironic that Windows are now a liability because of AI, given Microsoft’s priorities, no?

ABOUT THE AUTHOR


Kostas Farkonas

Veteran reporter and business consultant with over 30 years of industry experience in various media and roles, focusing on consumer tech, modern entertainment and digital culture.

Veteran reporter and business consultant with over 30 years of industry experience in various media and roles, focusing on consumer tech, modern entertainment and digital culture.