Home›Blog›Is AI really accelerating discovery? New data points to one field

Is AI really accelerating discovery? New data points to one field

Three simple trend lines side by side labelled cybersecurity, mathematics and algorithm design: the first rises steeply, the second rises gently, the third stays flat.
METR looked for a change of slope across three fields. Only one line bent sharply upward. (Illustrative)

Almost every week brings an announcement that an AI system has made some new discovery. A respected AI-evaluation group, METR, decided to stop taking those announcements at face value and instead plot the actual public record, looking for a real change of pace. Its answer, published on 14 August 2026, is more useful than the hype and more uneven. Across three areas it could measure, only one shows a sharp acceleration: the discovery of software security flaws. Maths has sped up modestly and is hard to measure. The design of faster algorithms, despite loud claims from the labs, shows no clear change at all. And even the security surge comes with a catch that matters for anyone worried about attacks.

This piece reflects reporting as of August 2026. The underlying figures are METR's own compilation from public databases, and METR says the data was gathered by AI agents and may contain errors, so treat individual numbers as indicative rather than exact.

What METR actually did

The method is deliberately unglamorous, which is the point. Rather than judge whether any single AI-assisted result was important, a task that quickly turns subjective, the team looked for a change of slope: is the overall rate of discovery in a field bending upward around the point where capable AI tools became widely used? They collected long-running public time series in three domains, cyber vulnerabilities, mathematics and algorithm optimisation, and marked early 2026 as the moment any AI effect should start to show. It is a blunt instrument, and the team is candid that some series are messy and that mistakes likely remain. That candour is part of why the exercise is worth reading.

The one field that clearly bent upward

The discovery of software vulnerabilities has accelerated sharply. METR's tallies, drawn from public bug databases, show the counts jumping across widely used software in 2026 compared with 2025: the OpenSSL encryption library and the cURL data-transfer tool both recorded several times as many reported flaws, Firefox and Microsoft's monthly security updates rose steeply, and the main aggregate databases had already matched their whole-of-2025 totals by early August. Some of the rise is explicitly credited to AI tools finding the bugs; much of it is not formally attributed but tracks the same curve. Mozilla has publicly described using an AI red team to harden Firefox, and Microsoft has told customers to expect more security updates as AI speeds up discovery. On the numbers, this is the field where the machines are visibly making a difference.


A wide funnel labelled vulnerabilities discovered pouring in at the top, with only a thin trickle labelled actually exploited coming out of the bottom.
The number of security holes being found has jumped, but the number attackers are known to be exploiting has grown far less. (Illustrative)

The catch: found is not the same as exploited

Here is the part the headline version leaves out. A vulnerability being discovered is not the same as one being attacked. METR notes that the databases tracking bugs known to be exploited in the wild, such as the US cyber agency's Known Exploited Vulnerabilities list, have grown far more slowly than the databases of bugs merely disclosed. The security firm Vulncheck, cited in the note, found that in the first half of 2026 the count of newly exploited vulnerabilities rose modestly while the count of newly disclosed ones rose several times faster. There is a lag between a bug being found and a bug being used, so this could shift. But on today's evidence, AI is flooding the pipeline of known weaknesses rather than unleashing a matching wave of real-world attacks. A great many of the extra findings are also low-severity. It is a genuine acceleration, and a narrower one than "AI is supercharging hackers" would suggest.

Maths: probably yes, but hard to prove

Mathematics is the middle case. The raw volume of work has ballooned, with submissions in some sub-fields climbing sharply, but volume is not the same as value. For a harder measure, METR looked at how quickly long-standing open problems from famous lists are being solved. A small number were cracked with AI help in 2026, including a counterexample to a decades-old conjecture and answers to problems on working mathematicians' lists. That is real, but it is a handful of results against a noisy historical baseline, and dating exactly when a problem was solved is notoriously difficult. The honest verdict is a likely acceleration that the available data cannot yet pin down with confidence.

Algorithm design: the dog that didn't bark

The most surprising result is the flat line. AI labs talk constantly about using their own models to find more efficient algorithms, and there have been eye-catching one-off records. Yet when METR assembled the dense, long-running leaderboards where such progress would show up, from speed-running the training of small language models to a fixed chess-engine benchmark to the theoretical limit on matrix multiplication, none showed a clear change of slope. The occasional AI-set record exists, but it sits inside the normal historical run of improvement rather than bending the curve. METR offers several possible explanations, including that labs may be making these gains privately and not publishing them, and plans a follow-up. For now, the public record simply does not show the optimisation boom the announcements imply.


A shield over a cluster of familiar software icons, with a magnifying glass scanning them for cracks.
UK businesses run the same software whose bug counts are climbing, which is why the finding cuts both ways for defenders. (Illustrative)

Why this matters for UK readers

Two things follow, and both are practical. The first is a general lesson in reading AI news: "an AI made a discovery" and "AI has accelerated discovery" are different claims, and only the second shows up in aggregate data. On this evidence it holds in one field and is unproven or absent in the others, which is worth remembering the next time a breakthrough is announced.

The second is closer to home. The software whose bug counts are climbing, Firefox, OpenSSL, Windows, is the same software running on British computers, in businesses, hospitals and government. A faster rate of vulnerability discovery cuts both ways: defenders who patch quickly benefit, while organisations that are slow to update face a larger stream of known weaknesses to worry about. Britain's AI Security Institute has made testing frontier models' cyber capabilities one of its core tasks, precisely because this dual-use edge is where AI's real-world impact is currently sharpest. The takeaway for a UK business is not panic but hygiene: the case for prompt patching just got stronger, because the machines helping the good side find holes are available to the other side too.

FAQ

Does this prove AI is not accelerating discovery?

No. It shows that, in the areas where progress can be measured in the public record, a clear acceleration appears in one, cyber-vulnerability discovery, is likely but unproven in maths, and is absent in algorithm design. It is a snapshot of measurable fields, not a verdict on AI's scientific value overall.

Is AI making cyber attacks more dangerous, then?

Not straightforwardly, on this data. The number of security flaws being found has jumped, but the number known to be actively exploited by attackers has grown far more slowly, and many of the new findings are low-severity. There is a lag between discovery and exploitation, so the risk could rise. For now the clearer effect is a bigger backlog of known bugs to fix.

Can I trust METR's numbers?

Treat them as indicative. METR is a well-regarded evaluation group and its data is public and open to correction, which is a point in its favour. But it also says the figures were compiled by AI agents and may contain mistakes, and several of the series are genuinely hard to interpret. The direction of the findings is more reliable than any single count.

Why would AI help find security bugs but not design faster algorithms?

METR is honest that it does not know. Possibilities include that huge amounts of money and effort are being poured specifically into AI-assisted bug hunting, that the two tasks suit current models differently, and that optimisation gains are being made inside labs but kept private. It flags this as one of the most interesting open questions and plans a follow-up.

The takeaway

The value of this note is that it refuses to round up. It would have been easy to collect the year's AI-discovery announcements and declare an across-the-board surge. Instead METR looked for the surge in the data and found it in exactly one place, with the honest caveat that even there the effect is narrower than it first appears. For readers trying to judge how fast AI is really changing the world, that kind of restraint, an acceleration you can point to and two you cannot, is far more useful than another breakthrough headline.

Sources

Enjoyed this? Get the weekly roundup:
← Back to blog