Microsoft argues AI makes secure software construction essential
David Weston, Microsoft's corporate vice president of AI security, argued at Black Hat USA 2026 that cybersecurity must shift from reactive to fundamentally defensive strategies. Historically, defenses relied on the scarcity of vulnerabilities and the high cost of exploitation. However, AI is changing this landscape by democratizing offensive capabilities.
Weston contended that accelerating patches remains reactive and leaves attackers a window of opportunity. Instead, he proposed investing AI-driven productivity gains into fundamentally safer construction, including memory-safe languages like Rust and formal methods that convert program logic into mathematical representations.
Practical results support this approach. Google reduced memory-safety vulnerabilities from 75% of its total in 2019 to below 20% by 2025, while 5 million lines of code in safer languages produced zero new issues of this type.