AI-Generated Security Reports: Can We Finally Trust Them?

Linux security expert Greg Kroah-Hartman giving a presentation on stage.
AI Summary

Linux kernel core developer Greg Kroah-Hartman has noted a dramatic improvement in the quality of AI-authored security reports, offering a cautious yet realistic view on the role of AI in the open-source ecosystem.

Imagine a massive digital library that tens of thousands of people check every day. The books in this library are managed by countless volunteers from around the world who write them one word at a time. Then, one day, an assistant named “AI” appears and starts finding errors in the books. At first, this assistant only spouted nonsense, but now it brings back surprisingly plausible error reports.

What if this library were the “Linux Kernel”—the core program connecting computer hardware and software, serving as the heart of almost every server and Android smartphone on Earth? Greg Kroah-Hartman, a central figure in this critical field, recently shared some fascinating insights about AI and security.

Why Does This Matter?

The Linux kernel is the foundation of the modern IT world. From the smartphones we carry to the internet services we use, nothing runs without Linux. Therefore, the security of Linux is directly tied to the security of everyone. Traditionally, finding security vulnerabilities in code was the exclusive domain of skilled developers. However, as AI makes its mark on this field, the speed and method of generating security reports are changing fundamentally. This demands new answers to the question of how we ensure the safety of the digital devices we use every day, moving beyond just changing the developer’s tools.

The Explainer

To put it simply, let’s compare the process of code inspection to “filters in a photo app.” Earlier AI used to apply excessive filters when inspecting photos, stubbornly insisting that random specks were bugs. Expert Greg Kroah-Hartman called this “slop.” But over the last month, these filters have become incredibly refined. Now, they have begun to expertly pick out only the real dust in the photo Ref 2, Ref 10.

Greg conducted an experiment through a branch called “clanker,” where AI-assisted tools actually found bugs in specific parts of the Linux kernel (such as ksmbd) Ref 4, Ref 9. This means AI has reached a level where it can go beyond simple writing and point out logical errors in complex systems. It’s as if an intern who just took their first steps has started accurately identifying typos in documents like a 10-year veteran.

Metaphorically, if previous AI security tools were like violent vacuum cleaners that made a fuss by shaking every book in the library, they have now become meticulous librarians who bring a magnifying glass to find the exact corners where dust has gathered.

Where We Stand

Greg Kroah-Hartman is a veteran who has been active in the Linux kernel security team since 2005 Ref 6, Ref 8. He maintains a “trust but verify” stance regarding information provided by AI.

Quite apart from AI’s ability to write reports well, he is very strict about “patches” (fixed code) that AI generates and sends in. He has a policy of preemptively rejecting patches in Linux driver and staging areas that are marked as AI-authored Ref 11. Why? Because code doesn’t just need to function—it must harmonize with the entire system. While AI understands the grammar of code well, it doesn’t perfectly grasp the philosophy of the massive ecosystem that is the Linux kernel. It’s similar to a robot that knows an excellent recipe but cannot consider human taste or the mood of the day.

What’s Next?

In the future, AI will become a powerful assistant that complements human eyes in the field of security. However, Greg’s actions teach us an important lesson: no matter how plausible AI-generated results may seem, the ultimate responsibility still rests with human experts. The open-source ecosystem will continue to engage in fierce discussions about how to efficiently handle the countless “security reports” raised by AI while safely incorporating “code” written by AI.

AI’s Take

From the perspective of a MindTickleBytes AI reporter, Greg’s attitude is not “technological skepticism” but rather “technical insight.” While AI is evolving from a simple learning model into an intelligent assistant, he reminds us that in a field where trust is paramount—security—”human judgment” remains the final security patch. His effort to uphold the “realm of ultimate responsibility” that humans must bear, rather than getting intoxicated by technological efficiency, is an essential process for healthy technological development.

References

  1. Keynote: Linux in the Land of LLMs - Greg Kroah-Hartman
  2. Linux kernel czar says AI bug reports aren’t slop anymore - The Register
  3. Greg Kroah-Hartman – Open Source Security Foundation
  4. While Torvalds Makes Peace With AI in Linux, Greg Kroah-Hartman Rejects AI Patches
  5. LLMs and the kernel security process - Netdev 0x1A
  6. 4 - Greg - oss_korea v2
  7. Kernel Recipes 2026 - Security in the LLM age - YouTube
  8. Untitled presentation - hosted-files.sched.co
  9. While Torvalds Makes Peace With AI in Linux, Greg Kroah-Hartman Draws a Line
  10. Greg Kroah-Hartman said that LLMs have become better at finding bugs - ProHoster
  11. Torvalds Softens AI Stance in Linux; Kroah-Hartman Draws Cautious Line
AD
Test Your Understanding
Q1. What stance does Greg Kroah-Hartman take regarding AI-generated patches?
  • He actively welcomes all AI patches
  • He preemptively blocks AI-generated patches in the driver/staging area
  • He automatically approves select AI patches
He preemptively rejects patches identified as AI-generated in the Linux kernel driver/staging area.
Q2. What is Greg's recent assessment of AI-authored security reports?
  • They are still of low quality and useless
  • The quality of reports has improved dramatically compared to the past
  • They are far superior to human-authored reports
He assessed that the quality of vulnerability reports generated by AI has improved dramatically over the last month and are no longer 'slop'.
Q3. What was the main purpose of the 'clanker' branch experiment conducted by Greg Kroah-Hartman?
  • To have AI rewrite the entire Linux kernel
  • To identify actual bugs using AI-assisted fuzzing tools
  • To replace open-source contributors
The 'clanker' branch was an experiment that used AI-assisted fuzzing tools to identify actual bugs in kernel code such as ksmbd and SMB.
AI-Generated Security Repor...
0:00