Quoting Daniel Stenberg

Simon Willison's Blog / 4/4/2026

💬 OpinionSignals & Early TrendsIdeas & Deep Analysis

Key Points

  • Daniel Stenberg describes a shift in AI-driven open-source security activity from low-quality “AI slop” reports to a larger volume of more conventional but still highly valuable security reports.
  • He notes the reporting volume remains intense, with many teams and developers producing or reviewing security findings at a high cadence.
  • The commentary implies that AI can still contribute meaningfully to security research outputs, even as signal-to-noise improves.
  • Stenberg indicates the workload of handling these security reports is substantial, potentially affecting developer time and incident-response workflows.
Sponsored by: WorkOS — Production-ready APIs for auth and access control, so you can ship faster.

3rd April 2026

The challenge with AI in open source security has transitioned from an AI slop tsunami into more of a ... plain security report tsunami. Less slop but lots of reports. Many of them really good.

I'm spending hours per day on this now. It's intense.

Daniel Stenberg, lead developer of cURL

Posted 3rd April 2026 at 9:46 pm