Google Built an AI That Hunts Its Own Security Bugs
Google's PageBreak agent autonomously finds and verifies real vulnerabilities in its own web apps, cutting through the flood of noisy AI-generated security reports.
Jose Antonio Lanz
Publisher Decrypt
Sep 25, 2026 at 7:16 PM UTC · 3 phút đọc

- Google disclosed PageBreak, an internal AI agent from its Product Security team that has found more than 500 bugs.
- Unlike typical AI scanners, PageBreak only reports a bug after confirming it with a working exploit against a live environment, giving it a near-zero false-positive rate.
- Google plans to pair PageBreak with CodeMender, its automated bug-fixing agent.
Google just gave one of its AI agents a new job: breaking into Google.
The company disclosed on September 24 that its Product Security team built an autonomous system called PageBreak, designed to hunt for real, exploitable vulnerabilities in Google's own web applications, according to a blog post by information security engineer Michał Bentkowski. The pitch is simple: an AI hacker that doesn't cry wolf.

“PageBreak is an internal AI agent of Google's Product Security team developed to test the security of our first-party web applications and address this challenge,” Google said. “Starting as a pilot in November 2025 and moving to a fully-fledged project in January 2026, its mission is to autonomously scale vulnerability discovery while minimizing manual toil.”
That matters more than it sounds. Security teams everywhere have spent the last couple of years drowning in "AI slop," Google explains, referring to the flood of low-quality, AI-generated bug reports that look plausible but turn out to be nothing.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
