Microsoft is about to make security updates more frequent. Using AI to detect vulnerabilities earlier in development so Windows 11 customers will receive more patches per month.
The logic is intuitive. More bugs found sooner equals more threats neutralized before attackers can weaponize them. The problem is that this logic has failed before, and Microsoft knows it.
In 2003, Microsoft introduced Patch Tuesday as a calculated fix for the chaos of ad-hoc emergency patching. The monthly cadence sounded disciplined — enterprises could plan, IT departments could test, attackers would face a moving target.
By 2015, the system had inverted itself. Patch Tuesday became a labor tax so severe that enterprises were hemorrhaging IT resources on compliance and testing rather than actual threat detection and response. Microsoft found itself besieged by customers demanding the ability to defer updates, to skip them, to manage the deluge. The company had created a security theater so expensive that it consumed the very labor needed to make security real.
An enterprise administrator might face a choice between deploying updates they don't fully understand or delaying them and risking exposure.
”What's repeating now isn't the format — it's the assumption underneath. Microsoft is betting that velocity solves the defender's dilemma against attackers who now have AI too. Patch frequency only works as defense if the people deploying those patches can actually keep pace without sacrificing judgment. The moment patching becomes a compliance burden rather than a threat response, defenders lose their advantage.
The variable this time is opacity. In 2015, IT teams could read a patch note and decide whether it mattered. AI-identified vulnerabilities may come with explanations too abstract or technical for humans to evaluate quickly. An enterprise administrator might face a choice between deploying updates they don't fully understand or delaying them and risking exposure. Neither choice is defense.