Key Takeaways

  • New AI-driven features aim to help device manufacturers process rapidly rising vulnerability volumes and telemetry data.
  • Regulatory pressure from the CRA, RED, and IEC 62443 is pushing companies toward automated evidence generation and compliance workflows.
  • Industry analysts highlight a broader industry shift toward AI-augmented cybersecurity to match adversary automation.

Manufacturers of connected devices have watched vulnerability volumes rise for years, but new forms of artificial intelligence are pinpointing software flaws faster than human teams can process them. This flood of findings shifts the priority from simply logging alerts to rapidly analyzing their relevance and risk impact.

This dynamic forms the context for a recent analysis released in Düsseldorf on June 23, 2026, by ONEKEY. The report indicates that AI models are uncovering significantly larger sets of potential vulnerabilities in smart products. According to Gartner predictions, roughly 60% of organizations will rely on cybersecurity platforms featuring AI-augmented automation by 2026. Smart factories, connected vehicles, medical devices, and industrial IoT generate continuous telemetry that expands the attack surface beyond what manual oversight can sustain.

Finding a flaw is not the same as knowing what it means for operational stability. The CEO of the company noted in the report that identifying a vulnerability does not automatically reveal its impact or provide documentation that satisfies regulatory auditors. Upcoming rules such as the Cyber Resilience Act (CRA) and the revised Radio Equipment Directive (RED) require manufacturers to prove which software components they ship and detail how known vulnerabilities are addressed.

Regulatory frameworks are establishing stricter expectations for automated assessments. The NIST AI Risk Management Framework and industrial standards like IEC 62443 dictate how evidence and documentation should be formatted. The growing demand for Software Bills of Materials (SBOM) and vulnerability exchange (VEX) information reflects these new compliance realities.

To address this, the ONEKEY platform analyzes device firmware directly at the binary level to automatically generate a software bill of materials and assess the relevance of detected vulnerabilities. While specific workload reduction metrics were not disclosed in the analysis, the automated approach targets common IoT weaknesses such as insecure communication channels and embedded credentials.

When firmware samples differ widely across manufacturers, machine learning systems surface additional software components automatically. Upcoming intelligent analysis assistants are being designed to further classify these findings and suggest remediation priorities.

Industry analysts emphasize that attack automation is accelerating on the adversary side, pushing defenders toward higher levels of automated response. This environment drives investments in agentic AI systems that guide manufacturers through risk assessments and compliance requirements with fewer manual steps.

Beyond regulatory pressure, market dynamics reflect this shift. MarketsandMarkets projected an AI-driven cybersecurity market size of roughly $25 billion by 2026. Smart manufacturing reports from organizations like NuHarbor Security echo that IoT expansion places heavy strain on traditional programs, necessitating structured product security processes.

Integrating tools like a compliance wizard that aligns with IEC 62443-4-2 and ETSI EN 303 645 prepares device manufacturers for impending regulatory requirements. Many device makers still rely on manual spreadsheets for SBOM and compliance tracking, but transitioning to automated platforms offers structured, traceable evidence as auditors enforce tougher scrutiny.

The firm's participation in the EU-funded CRACoWi project alongside 13 European partners to build an AI-powered assistant for CRA compliance suggests that conformity assessments will lean heavily on guided workflows. Lowering the compliance barrier is particularly vital for small and midsize manufacturers handling complex IoT portfolios.

Other major technology vendors are reinforcing the shift toward automation. Microsoft and IBM integrate AI into anomaly detection for IoT security, while CrowdStrike emphasizes autonomous workflows across network endpoints. These parallel developments highlight a competitive market moving rapidly toward security automation at scale.

Automated prioritization of vulnerabilities shortens remediation cycles for Product Security Incident Response Teams. In industries where connected devices remain deployed in the field for a decade or more, streamlining vulnerability triage reduces exposure windows and establishes a more manageable operational baseline.

The combination of rising vulnerability volumes, expanding regulatory requirements, and maturing AI diagnostic tools is establishing a highly automated operational standard for product security.