Isn't the other half of AI that we can afford to look for exploits in one-off software?
To be at risk, you'd first need to publish your application. The attacker would separately have to figure out how to identify and access your computer for attack.