AI SafetyResearch 🇺🇸 06.08.2026 16:01

AI fails to properly patch software flaws 74% of the time, 1Password's study warns

AnthropicAnthropic OpenAIOpenAI
A new study by 1Password's Off-By-1-Labs reveals that AI-generated patches for security vulnerabilities are largely ineffective, with only 26% of patches being usable. The study highlights that LLMs often produce flawed fixes that introduce new bugs or alter application behavior.
1Password's security research team Off-By-1-Labs published a study testing the effectiveness of AI models in patching software vulnerabilities. The team hypothesized that frontier AI models would achieve around 67% patch success, but results were significantly lower at only 26% usable patches. Researchers selected six recently disclosed vulnerabilities in open-source software to test models like Claude and an LLM based on OpenAI's Codex. The models generated 6,080 patch attempts across different conditions and prompts. Findings showed that 21% of patches fixed the bug but altered application behavior, and 53.9% of attempts failed, introduced new bugs, or both. The team coined the term 'FLAWED' for these fix-like artifacts with embedded defects, highlighting that AI-generated patches often appear to work but fail to fully resolve vulnerabilities and may introduce new issues. 1Password released its FLAWED tooling on GitHub for further research. Keith Hoodlet, head of Off-by-1 Labs, emphasized that human oversight is paramount and AI should be used for vulnerability triage, helping defenders prioritize impactful bugs. The study suggests AI is not yet ready for autonomous patching but can assist in cyberdefense.
Abbreviations
LLM = Large Language Model — большая языковая модель
CVE = Common Vulnerabilities and Exposures — общие уязвимости и экспозиции
API = Application Programming Interface — программный интерфейс приложения
Source: ZDNet AI — original
Our earlier posts on this topic ↓
Fresh news