Google’s Product Security team announced an autonomous agent called PageBreak that searches for exploitable weaknesses in the company’s own web applications. Launched as a pilot in late 2025 and expanded in early 2026, the system aims to scale vulnerability discovery while cutting down the manual effort traditionally required for security testing.

How the system validates findings

Unlike many AI-based scanners that generate large numbers of false alarms, PageBreak only reports a flaw after a dedicated validator constructs a working exploit against a live copy of the target application. This two-step process, built on Google’s Gemini models, ensures that each reported issue is demonstrably exploitable, eliminating the “AI slop” of plausible-looking but non-existent bugs that have plagued security teams recently.

Early results and the bug landscape

Since its deployment, PageBreak has uncovered more than 500 cross-site scripting (XSS) vulnerabilities across Google’s first-party sites. XSS bugs can allow attackers to hijack user sessions, exfiltrate data, or impersonate users. When the agent was run against applications built with Google’s newer high-assurance web frameworks—designed to make entire classes of bugs impossible—it identified only two issues, providing concrete evidence that secure-by-design development reduces the attack surface.

Integration with automated remediation

Google plans to pair PageBreak with CodeMender, an internal tool that automatically generates code fixes for confirmed vulnerabilities. The envisioned workflow would have PageBreak confirm a flaw, hand it to CodeMender for a suggested patch, and present engineers with a ready-to-review fix, streamlining the remediation cycle.

Context within the broader AI-security debate

The launch comes amid growing concerns about AI-enabled cyberattacks. Earlier this year, more than a hundred organizations, including major tech firms, warned that AI agents were increasingly being used to breach real systems. By turning the technology inward, Google hopes to stay ahead of potential adversaries, using the same capabilities that could be weaponized to proactively secure its services.

Why it matters

PageBreak demonstrates a shift from reactive security to proactive, AI-assisted defense. Its low false-positive rate and ability to automatically propose fixes could set a new standard for how large enterprises manage software risk. If successful, the model may inspire similar implementations across the industry, raising the overall bar for vulnerability detection and remediation.

Why it matters

The system showcases how powerful internal AI resources can be leveraged to protect massive codebases, potentially reducing the time and cost associated with traditional security audits. By coupling detection with automated patch generation, Google aims to create a faster, more reliable loop for fixing bugs before they can be exploited elsewhere, influencing best practices for security teams worldwide.