Microsoft claims it can use AI to distinguish between security and non-security bugs 99% of the time, plans to open-source the methodology in coming months
Microsoft claims to have developed a system that correctly distinguishes between security and non-security software bugs 99% of the time …
Context & Ripple Effects
Bug classification at Microsoft has been a manual discipline for years: back in 2018, MSRC published its internal procedures for prioritizing and classifying security reports for the first time, codifying how humans decide which bugs matter. The pipeline has since been automated at both ends — MDASH now orchestrates 100+ AI agents to find vulnerabilities, and the resulting volume shows in a record-setting June 2026 Patch Tuesday fixing nearly 200 flaws.
This announcement fills the middle of that pipeline: an AI classifier that separates security-relevant bugs from ordinary ones with claimed 99% accuracy, with the methodology to be open-sourced. That follows Microsoft's earlier playbook of shipping security tooling openly, as it did when it open-sourced the Counterfit AI risk-assessment tool in 2021.
First-order effects
- MSRC's triage teams get a filter for the growing inflow of AI-discovered findings, deciding which of the nearly 200-flaw-scale monthly queues get security engineering attention first.
- Security researchers filing reports face faster and more consistent severity verdicts on their submissions, since classification no longer depends solely on manual reviewer judgment.
Second-order effects
- Open-sourcing the methodology hands rival vendors and bug-bounty platforms a ready-made template, pressuring them to adopt or publish comparable classifiers rather than keep triage criteria proprietary.
- With discovery (MDASH), classification (this system), and patch delivery (Patch Tuesday) each AI-assisted, tooling vendors and enterprise security teams can reprice around throughput rather than headcount.
Third-order effects
- If the pattern holds, vulnerability management consolidates into end-to-end AI pipelines — find, classify, patch — making the open publication of methodologies a competitive norm and shifting the scarce resource from analyst time to validated model accuracy.
- Widely shared classification models also create a common standard for what counts as a security bug, which regulators and insurers could eventually reference when judging vendor patching diligence.
The trend: Microsoft is assembling an AI-driven vulnerability lifecycle — autonomous discovery via MDASH, automated triage via this classifier, and record-scale patching — moving security operations from human-queued to machine-pipelined.