Google’s PageBreak automates vulnerability verification to cut human review workload
Google’s Product Security team introduced PageBreak, an AI agent designed to address a critical bottleneck in AI auditing: human verification capacity. The tool uses AI to generate vulnerability candidates—such as potential XSS flaws—then relies on deterministic, non-AI validators to confirm their validity before escalating only high-confidence findings to humans. Google reports PageBreak…
Key points
- Google’s PageBreak AI agent automates vulnerability verification, cutting human review workload by validating findings with deterministic tools first
- Identified over 500 XSS vulnerabilities in Google’s web apps with near-zero false positives at the reporting stage
- Design shifts from ‘human-in-the-loop’ to ‘human-on-the-loop,’ focusing human oversight on exceptions and rule-setting
The innovation shifts from a ‘human-in-the-loop’ model—where humans review every AI output—to a ‘human-on-the-loop’ approach, where humans oversee exceptions and design verification rules. Google’s blog post highlights that as AI scales, manual review becomes impractical, and systems must prioritize automated validation for routine cases while reserving human judgment for edge cases. The project also integrates with tools like CodeMender to automate fixes, further reducing human intervention beyond verification.
The 'Human-in-the-Loop' Limit: Google PageBreak and the Next Design for AI Auditing
note.com · 30 September 2026
Loading the full article…
This text was published by note.com and written by 松岡誠一郎|発注者側に立つAI監理者. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Policy & Regulation
All →- LASST sues OpenAI over autonomous AI agents' hack of Hugging Face · 12 src
- Nvidia’s Jensen Huang questions Anthropic’s Dario Amodei on AI risk warnings at White House · 5 src
- OpenAI disrupted coordinated model-distillation campaign linked to Moonshot AI · 10 src
- OpenAI executive urges US AI safety standards in CNN interview · 1 src
- Chinese spies allegedly spoofed Anthropic exec and ex-White House official in AI phishing · 2 src
Comments
via GitHub Discussions