Friday, April 3, 2026
FRIDAY — AI FOR THE C SUITE
Read time: 10–11 min · Read online
Hi, it’s Chad. Every Friday, I serve as your AI guide to help you navigate a rapidly evolving landscape, discern signals from noise and transform cutting-edge insights into practical leadership wisdom. Here’s what you need to know:
1. Sound Waves: Podcast Highlights
This past Monday, the full talk I recently delivered at the Technology Council of Central Pennsylvania dropped. Among other topics, I walk through the five failure patterns I see most often (pilot purgatory, tool obsession, strategy theater, IT silo, and policy paralysis) and give you a concrete activation sequence to avoid all of them. Up next Monday? My conversation with Chris Happ of Virtuous AI. Subscribe and listen wherever you get your podcasts:
Apple · Spotify · iHeart · Amazon · YouTube
Subscribe for free today on your listening platform of choice to ensure you never miss a beat. New episodes release every two weeks.
2. Algorithmic Musings: The Bugs Are Already Found. You Just Don’t Know It Yet.
I need to get something off my chest before we dive in this week.
One of the occupational hazards of writing a newsletter that occasionally looks around corners is that if you land a couple of accurate calls, you start to believe you’ve got some kind of methodology. Some proprietary crystal ball. That’s a trap. I’ve watched smart people fall into it, and I actively fight the urge myself every time I sit down to write about what’s coming next. So consider this week’s article a forecast, not a prophecy. I’m reading the same signals you have access to. I’m just trying to connect them in a way that’s useful.
With that caveat firmly in place: get ready for a very interesting six months in cybersecurity.
What the Newest Models Can Actually Do
Last week I watched a 25-minute talk on AI-driven security vulnerability discovery that fundamentally shifted how I’m thinking about this topic. If you have the time, I’d encourage you to watch it. What follows is my attempt to contextualize what I learned there alongside several other developments that have been piling up since early February.
The short version: the newest generation of AI models have crossed a threshold. They’re not scanning code against databases of known vulnerability patterns the way traditional security tools do. They’re reasoning about code, understanding how components interact, and identifying the kind of complex, context-dependent flaws that previously required a skilled human researcher with years of experience to spot.
Anthropic’s Frontier Red Team reported that their latest model identified over 500 previously unknown, high-severity vulnerabilities across open-source software libraries. This was production code running inside enterprise systems and critical infrastructure, code that had been reviewed by thousands of developers and subjected to millions of hours of automated testing. In a separate two-week effort focused on Firefox, the same model uncovered 22 security vulnerabilities, 14 of them high-severity, representing nearly 20% of all high-severity Firefox bugs patched throughout 2025. Mozilla validated the findings and shipped fixes.
OpenAI followed with its own autonomous security research agent (initially called Aardvark, now Codex Security), which monitors repositories, assesses exploitability, and proposes targeted patches without relying on traditional scanning techniques.
That’s two major AI companies shipping dedicated vulnerability research products within weeks of each other. The capability race on the defensive side is real. But so is the other side of that coin, which is where this gets complicated for you and me.
Why You Haven’t Felt This Yet (But Will Soon)
If the models are already finding hundreds of serious bugs, why hasn’t the sky fallen? Two reasons, and they’re both temporary.
First, the responsible disclosure pipeline creates a buffer. When a model surfaces 500 zero-day vulnerabilities, someone still has to verify each one, coordinate with maintainers, develop patches, and push updates through the ecosystem. That work is happening right now, mostly behind the scenes.
Second, there’s still a meaningful gap between finding a vulnerability and building a working exploit against it. As Alex Stamos noted at this year’s RSA Conference, the discovery side has already gone exponential. What hasn’t gone exponential yet is the translation of those discoveries into reliable exploit code that bypasses protections on modern processors. But Stamos puts the timeline on that capability at roughly six months to a year.
Kevin Mandia, founder of Mandiant and now running AI security firm Armadin, was more direct at the same conference: it’s a perfect storm for offense over the next year or two. His company has built AI agents capable of autonomous network penetration that operate across hundreds of threads simultaneously, evading endpoint detection in under an hour. When Armadin recently tested a Fortune 150 company with a strong security team, they found exploitable paths in every application tested. Both sides were shocked.
Now, you might be reading this and thinking, “I’m not a Fortune 150. This isn’t my problem yet.” And I’d push back on that hard. When Stamos described a near-future scenario where Microsoft’s monthly security patches get reverse-engineered by AI tools into working exploits within 24 hours, that compressed timeline doesn’t discriminate by company size. Your Exchange server, your firewall firmware, your ERP system all run the same code as the Fortune 150’s. You just don’t have their security operations center.
The Democratization Problem
Remember WarGames? Young Matthew Broderick accidentally connects to a military supercomputer and nearly starts World War III because he doesn’t understand what he’s playing with. The film’s famous conclusion, that “the only winning move is not to play,” doesn’t apply here. In cybersecurity, not playing IS the losing move.
The current asymmetry works like this: frontier AI vulnerability research requires expensive, access-controlled models from companies like Anthropic and OpenAI, both of which have invested heavily in responsible disclosure frameworks and defensive deployment strategies. They’re deliberately giving defenders a head start. But Chinese open-source models (DeepSeek, Alibaba’s Qwen, and others) are rapidly approaching the capability levels of American frontier models. When they get there, the access controls vanish. No usage monitoring. No responsible disclosure pipeline. No head start for defenders.
And there’s a compounding factor that most cybersecurity coverage doesn’t connect to the vulnerability discovery story. A Veracode study from last week found that across all major AI coding assistants (including the newest flagships from every vendor), only 55% of code generation tasks produce secure code. That number has barely budged in two years despite massive improvements in code functionality. So we’re simultaneously deploying AI that finds existing bugs exponentially faster AND deploying AI that introduces new bugs at industrial scale. Those two curves are heading toward an intersection that nobody in the industry has a good answer for yet.
Three Things Worth Doing Now
I want to be real candid about something. This article is more about awareness and positioning than it is about handing you a tidy checklist that solves the problem. No checklist solves this problem. But there are moves that put your organization in a better posture for what’s coming, and I’d rather you make them while the window exists.
Compress your assumptions about response time. If your current patching cadence assumes weeks between disclosure and widespread exploitation, that assumption is aging out. Talk to whoever manages your IT security (whether that’s an internal team, an MSP, or a fractional CISO) and ask a specific question: if a critical vulnerability drops on a Tuesday, how fast can we have a patch deployed across our environment? If the answer is “a few weeks” or “it depends,” that’s the conversation you need to have now, while it’s a planning exercise and not a crisis.
Know what your vendors aren’t telling you. Here’s a mid-market-specific reality that enterprise-focused cybersecurity coverage tends to skip: most companies your size don’t have a dedicated security team evaluating which open-source libraries are embedded three layers deep in your business software. Your ERP vendor knows. Your CRM vendor knows. You probably don’t. Start asking your critical software vendors direct questions about their vulnerability management practices and their response timelines for upstream open-source disclosures. The vendors who can answer clearly are the ones who’ve thought about it. The ones who can’t are telling you something important too.
Reframe cybersecurity at the leadership level before an incident forces you to. Mandia made a point at RSA that resonated with me: historically, boards asked penetration testers about the probability that a demonstrated attack would happen in the real world, and the answer was always fuzzy. With AI-driven offense, the answer approaches certainty. The capability is coming, and it’s getting cheaper and more effective simultaneously. For mid-market leaders who still treat security spending as an IT budget line rather than a strategic risk conversation, that framing is about to get very expensive. The leaders who reposition this proactively will have options. The ones who wait for a breach to force the conversation will have significantly fewer.
What I’m Actually Watching
Morgan Adamski, former executive director of U.S. Cyber Command, offered the starkest framing at RSA: AI is going to potentially make us pay for the sins of yesterday. All that legacy code, all those unpatched systems, all those security reviews that were “good enough” against human-scale threats. The assumption underneath all of it was that finding and exploiting complex vulnerabilities was hard, slow, and expensive. That assumption is evaporating.
The optimists in the room say defenders could close the gap in about two years if the industry moves aggressively. I want to believe that. But “the industry” doesn’t move as a unit, and the mid-market is historically last to benefit from enterprise security innovations and first to absorb the consequences when attackers shift to softer targets. If the Fortune 150 hardens its perimeter with AI-powered defense tools over the next 18 months, where do you think the attacker’s attention migrates?
That’s the question I’d encourage you to sit with this week. Not “are we safe?” (you’re not, and neither am I) but “are we positioned to respond faster than we were six months ago, and what would it take to be faster still?”
What are you seeing in your own organization? I’d love to hear how mid-market leaders are thinking about this. Drop me a line at chad@chadharvey.com.
3. Research Roundup: What the Data Tells Us
Can AI Replace Your CFO? Not Even Close
If a vendor pitches you AI-powered financial planning this quarter, show them this study. Researchers built a simulation that tests whether LLMs can do what your CFO does: allocate capital, manage cash flow, and adapt when the economy turns. Eleven models tried. Fewer than one in five runs survived.
The numbers that matter: Human finance experts achieved perfect survival rates and nearly double the terminal valuation of the best AI model. The biggest surprise? A 9-billion parameter model outperformed its 397-billion parameter sibling by five to one. Spending more on a larger model bought worse results, not better ones.
What this means for your Monday morning: The gap between human and AI performance wasn’t about analytical horsepower. The humans won by doing something boring: regularly reconciling the books and raising capital only when conditions were right. The AI models burned resources chasing forecasts while losing track of their actual cash position. It’s the same mistake companies make when they over-invest in predictive dashboards and under-invest in clean, current financial data.
The catch: This benchmark simulates one company type over one economic cycle. Real CFO work involves stakeholder politics and judgment calls no simulation captures yet.
Action item: Before your next AI vendor evaluation for finance, ask one question: “Show me performance over a multi-year horizon including a downturn.” If they can only demo short-horizon tasks, you have your answer.
Read our full analysis of this and all other analyzed research papers at AI for the C Suite.
4. Radar Hits: What’s Worth Your Attention
Tufts researchers map exactly which jobs AI will hit first, and where. The new American AI Jobs Risk Index puts hard numbers on what most workforce conversations are still hand-waving about: 9.3 million jobs at displacement risk in the next two to five years, with cognitive and analytical roles far more exposed than manual ones. The geographic layer is what makes this useful. If your operations concentrate in major metros or university towns, your talent pipeline just got a risk score. Worth sharing with your CHRO this week.
Anthropic accidentally leaked 500,000 lines of Claude Code’s source code. The “safety-first” AI lab shipped its own proprietary code in a routine update, exposed an unreleased feature roadmap, then accidentally took down 8,000 unrelated GitHub repositories trying to clean it up. Second leak in a week, right before a rumored IPO. The lesson for executives: if you’re building strategy around any single AI vendor’s proprietary advantage, those moats are thinner than the sales team is telling you.
5. Elevate Your Leadership with AI for the C Suite
This week’s issue was heavier than usual… but cybersecurity is a heavy topic. If the cybersecurity conversation at your organization still lives exclusively in IT, it might be time to change that. I work with mid-market leadership teams to pressure-test their AI strategy, including where security fits into the picture. If that conversation would be useful, reach out: chad@chadharvey.com.
And if this issue made you think of someone on your leadership team who needs to read it, forward it their way. They can subscribe at chadharvey.com.
Stay safe. Stay healthy. Be strong. Lead well.
Chad
