Microsoft has explained how generative AI and large language models are now woven into its vulnerability management work. The goal is to shorten the gap between finding a flaw and protecting customers, with priority given to higher-risk areas.

AI is now brought in earlier in the development cycle, but humans still handle the assessment, the risk trade-offs and the final quality checks to make sure fixes meet the expected standards.

The change is already affecting update volume. After June’s Patch Tuesday set a record with nearly 200 flaws fixed, Microsoft says customers should expect more security updates in each release. The company stresses that this reflects better detection and handling of problems, not a decline in Windows security.