Managers Use AI for Reviews as Google Warns of Faster Exploits
Separate reports show managers using AI for performance feedback and cybercriminals using it to weaponize known software flaws faster, raising concerns about workplace decisions and patch urgency.
Headway's survey of 1,000 managers found that 33% had used AI to write feedback or prepare a performance review, 31% had turned to AI to resolve team conflicts, and 27% had used it to help write uncomfortable conversations they needed to have. The 33% figure is down from 41% in a similar survey a year ago, but remains high. Separately, 57% of managers said they had scripted or rehearsed a difficult conversation before having it using AI.
Thalia-Maria Tourikis, a qualified health coach and burnout prevention and recovery expert at Headway, said managers should not hand over emotionally sensitive conversations to automation. “When human emotions such as trust and empathy are involved, it is best conveyed when written by a person,” she said. “The perfection of AI reads as superficial and doesn't have the same impact.”
Workers are also concerned about AI monitoring. Owl Labs' State of Hybrid Work survey of 8,000 workers worldwide found that 58% of employees believe their employer has deployed AI-based monitoring tools. The Headway survey does not make clear whether managers are using AI only to improve grammar or to generate the entire text of a performance review. That distinction matters because performance reviews are often linked to financial compensation, including annual salary and raises.
Google's Threat Intelligence Group said in its Vulnerability Discovery and Exploitation Trends in the AI Era paper that AI is already having a measurable impact on the vulnerability landscape. The number of flaws discovered each month rose from 5,045 in January 2026 to 10,740 in August 2026. During the same period, the average number of flaws exploited in the wild rose from 10.5 a month in 2025 to 18 a month.
Zero-day exploitation rose only marginally, from 8 a month in 2025 to 11 a month this year, Google said. The bigger threat, according to GTIG, is the rapid weaponization of n-day flaws. “It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the report states.
Google said the number of exploited high-risk flaws doubled year on year. AI-discovered vulnerabilities also skew toward higher severity: 50% resulted in remote code execution, compared with 26% across the broader vulnerability ecosystem. GTIG said the security community is using AI primarily for high-level flaws in critical infrastructure, privilege boundaries, core libraries, and runtime environments. One example was CVE-2026-1731, a command-injection vulnerability in BeyondTrust products discovered by a third-party AI research agent. Google said threat actors began exploiting the flaw within days of public disclosure, using it in campaigns that included privilege escalation, data theft, and malware deployment.
Google expects vulnerability discovery and exploitation to continue growing in the short to medium term. It said organizations must move away from broad, unprioritized patching programs and toward intelligence-driven vulnerability management. “To counter the increased risk from rapid vulnerability discovery and exploitation, organizations must transition from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge-defense with automated, agentic remediation,” Google said.