Quoting Greg Kroah-Hartman

Simon Willison's Blog / 4/4/2026

💬 OpinionDeveloper Stack & InfrastructureSignals & Early TrendsIdeas & Deep Analysis

Key Points

  • Linux kernel maintainer Greg Kroah-Hartman says that earlier AI-generated security reports were low quality and often incorrect, but were not concerning at the time.
  • He reports that within roughly a month, the quality baseline changed, with “real” security reports now being produced by AI.
  • Kroah-Hartman claims that open source projects are generating security reports using AI that are both good and credible, not merely “AI slop.”
  • The post is presented as a quotation/selected insight rather than a full technical guide or research finding.
Sponsored by: WorkOS — Production-ready APIs for auth and access control, so you can ship faster.

3rd April 2026

Months ago, we were getting what we called 'AI slop,' AI-generated security reports that were obviously wrong or low quality. It was kind of funny. It didn't really worry us.

Something happened a month ago, and the world switched. Now we have real reports. All open source projects have real reports that are made with AI, but they're good, and they're real.

Greg Kroah-Hartman, Linux kernel maintainer (bio), in conversation with Steven J. Vaughan-Nichols

Posted 3rd April 2026 at 9:44 pm