I don't think enough people grasp the sheer volume of critical, or at least highly important software that powers our world. It totally makes sense to use these frontier models to harden Wordpress, or libcurl, or specific OS APIs etc. However, it doesn't seem like we're anywhere near the point where it is economical to point frontier LLMs at every network-facing piece of software as easily as running a Nessus scan. Until we get to that point, there will probably be (AI-assisted) consultants doing their best on source code reviews. I'm also skeptical of the sudden "security at any cost" story that's being told today. Since when are companies _actually_ willing to shell out the cash to secure their systems? At what token cost will we start to see organizations start to go back to doing the bare minimum?
I agree with most of this. Just wanted to point out the AI-Assistaht Consultant route is very feasible. I just paid for all of my AI subscriptions this year with my first bug bounty and still had smoothest hand left over to use for fun.