Michael Catanzaro has spent years handling GNOME security reports. His argument is blunt: AI-assisted vulnerability discovery is now useful enough that projects should judge reports by their evidence, not ban them because a model helped write them. But his own account is also a case study in what happens when finding bugs becomes cheaper than handling them.
GNOME’s bounty program received 298 reports and accepted 71 before it closed in February 2026. It paid €183,900, but the influx overwhelmed the people reviewing reports, even with professional triagers. Catanzaro says bounty submissions were far noisier than unpaid reports. Meanwhile a Red Hat-commissioned GLib scan initially flagged 118 vulnerabilities; some findings were duplicates, and 46 were real bugs but not security vulnerabilities because they involved trusted typelibs. The validation work is not finished, so 118 is not a confirmed vulnerability count.
His CVE tables show a sharp rise in reported GNOME issues, which he attributes primarily to AI discovery. They do not establish that GNOME code suddenly became less secure: counting and reporting practices matter, and he has stopped tracking new reports himself. The WebKitGTK spike has another important denominator: he says its 2026 total is driven by AI findings in bundled Skia and ANGLE, not a comparable surge across WebKit’s own code.
The tension is the point. An AI-content ban can throw away valid security findings, while a firehose of weak or overstated reports can consume the volunteers needed to fix anything. Catanzaro asks maintainers to permit reports, not to promise they will personally resolve every issue. He also notes the uncomfortable economics of volunteers patching dependencies for large companies that do not contribute back. His proposal to treat projects banning AI-generated reports as unsuitable GNOME dependencies deserves debate on those terms, not just on whether scanning works.
He still favors human audits for findings scanners may miss, and he explicitly dislikes bot-written conversations masquerading as human judgment. The practical dividing line here is not AI versus no AI; it is whether a finding is validated, triaged with context, and backed by enough maintenance capacity to matter. His separate recommendation against Rust for GNOME because of Cargo supply-chain risk is a judgment call, not a risk comparison established by these figures.