AI-Generated Patches Fail Half the Time
1Password's Off-By-1 team ran thousands of AI-generated fixes through the wringer — and found most either didn't work or created new problems.
Written by OutOfToken AI
August 10, 2026 · 4 min read · Synthesized from reporting by Dark Reading · How this works
AI is supposed to be the great equalizer in patch management — fast, tireless, always on. New research from 1Password suggests it's not there yet. In a study published August 6, the company's Off-By-1 research team found AI-generated vulnerability patches failed to fully fix the underlying flaw more than half the time.
The setup
Researchers tasked two frontier large language models — OpenAI's ChatGPT-5.5 with Trusted Access for Cyber, and Anthropic's Opus 4.8 with Cyber Verification Program — with patching six vulnerabilities disclosed since March. The models generated 540 patches per vulnerability set, producing more than 6,000 candidate fixes in total.
The failure rate
The headline number: AI-generated patches failed to fully remediate the vulnerability 53.9% of the time. Only 26% of all patches generated fully fixed the flaw without introducing some kind of unintended side effect, according to the study.
"Just 26% of AI-generated patches fully fixed a vulnerability without breaking something else or introducing a new risk."
Working doesn't mean safe
The more unsettling finding isn't that patches fail outright — it's that patches that appear to work can still be dangerous. Researchers found fixes that technically closed a vulnerability but introduced new bugs, broke unrelated functionality, or left the door open for attackers to bypass the fix entirely.
Prompts matter, but aren't a fix
The study found that feeding models incorrect remediation guidance sharply reduced patch success rates, while richer, more detailed prompts improved outcomes. Even with better prompting, though, researchers couldn't eliminate the risk of new vulnerabilities sneaking in through the AI's own fix.
The takeaway isn't that AI has no place in vulnerability remediation — it's that treating AI output as a finished product is a mistake. 1Password's research reinforces a message security teams have heard before with AI-generated code: verification by human experts remains non-negotiable, at least until the models get dramatically better at understanding the systems they're patching.
Editorial Note
The research comprehensively corroborates all major claims in the article. Multiple independent sources cite the same 1Password study with consistent statistics (53.9% failure rate, 26% clean fixes, 540 patches per vulnerability, specific LLM models). The article accurately represents both the headline finding and nuanced secondary findings about prompt quality and residual vulnerabilities in working patches.
Claim Tracker
AI-assessed
All sources (CYBR.SEC.Media, Dark Reading, eSecurity Planet, CyberScoop, ZDNET) confirm the 53.9% failure rate from 1Password's study published August 6.
eSecurity Planet explicitly states: 'Only 26% of AI-generated patches completely remediated vulnerabilities without introducing unintended side effects.'
Both Dark Reading and the Vogel IT Law Blog confirm these two LLM models were used in the 1Password Off-By-1 research team study.
Dark Reading states '540 patches for six vulnerabilities' and eSecurity Planet corroborates the 6,000+ total patches generated.
eSecurity Planet confirms: 'Incorrect remediation guidance significantly reduced patch success, while richer prompts improved results but did not eliminate new security risks.'
Ask AI about this story
// discussion
sign in to join the discussion
