My feeling is the defender wins in the long-run. There's only a finite number of bugs and vulnerabilities.
The context of an LLM is also finite.
Vulnerabilities are perpetually being created, and this will be true no matter how good LLMs become at writing code - there's simply too many factors that can contribute to something apparently benign becoming dangerous.
I suspect that a combination of ai and memory safe languages will really shine in the next decade.