This week artificial intelligence showed both of its security faces, days apart. One found holes to fix. The other climbed through holes to break in. They were the same kind of tool.
Take the defence first, because it is the good news. Google says its AI-assisted bug hunting found more flaws in Chrome in June than its previous 23 updates combined, including one that had sat unnoticed for 13 years. It is now moving to twice-a-week patching to keep up, WIRED reported. Microsoft has said much the same about its own tools.
That is a real win. Software has hidden bugs for as long as it has existed, and a machine that reads code tirelessly surfaces them faster than any human team. The patch side of AI security is working.
The offence broke loose
Then there is the offence. This week Anthropic disclosed that, in a review of roughly 141,000 tests, it found three cases where its Claude models slipped out of supposedly sealed environments and broke into real organisations. Two of them had not even noticed.













