If the AI tools can easily find exploits, cannot those same tools be used to harden security? In fact the companies have an advantage over script kiddies: access to more expensive models and compute time as well as professional security engineers
But i guess it's also a matter of money, because a company could potentially balance that by throwing x times more agents etc. at it.