According to Root.io, your security backlog is a problem that only AI can fix
Summary
Root.io, an agentic, open-source security company acquired by Aikido as of June 30, 2026, automates vulnerability remediation across the software supply chain. CEO Ian Riopel contends that AI-powered attacks necessitate AI-powered defenses, as traditional vulnerability management and "latest version" updates are no longer sufficient. The "latest" can introduce new risks, exemplified by Shai-Hulud supply chain attacks. Root.io proposes surgical backporting to patch specific code lines, avoiding wholesale upgrades. AI coding tools exacerbate the issue by increasing open-source dependencies and generating overwhelming alerts. Root's agentic systems automatically resolve over 95% of vulnerabilities, with human oversight for critical cases. Riopel advocates a "shift out" approach, removing security burdens from developers by silently fixing vulnerabilities, aiming to eliminate backlogs and achieve zero CVEs.
Key takeaway
For AI Security Engineers managing escalating open-source supply chain risks, your traditional vulnerability management strategies are now insufficient. You must adopt AI-powered agentic systems to automate remediation, as human teams cannot keep pace with AI-generated threats and alerts. Prioritize surgical backporting over full version upgrades to mitigate new attack surfaces. Shift security responsibilities away from developers to ensure continuous, silent vulnerability resolution, aiming to eliminate backlogs and achieve zero CVEs.
Key insights
AI-powered defense is crucial to counter the escalating, AI-driven open-source vulnerability crisis.
Principles
- "Latest" software versions can introduce new attack surfaces.
- Surgical backporting reduces risk.
- AI agents automate most vulnerability remediation.
Method
Root.io's agentic systems use specialist AI agent "swarms" to automatically resolve over 95% of vulnerabilities, with human validation for the remaining 5% and production deployments.
In practice
- Implement surgical backporting for patches.
- Automate vulnerability remediation with agents.
- Shift security tasks away from developers.
Topics
- Open-source Security
- Vulnerability Management
- Software Supply Chain
- AI-powered Defense
- Agentic Systems
- Surgical Backporting
Best for: CTO, VP of Engineering/Data, AI Security Engineer, Director of AI/ML, MLOps Engineer
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by Insight Partners.