I dunno man, if there's a deluge of new AI generated code at all layers of the stack I think there will still be vulnerabilities.
Like if we were willing to stop adding new code and just have a small secure code base, AI could maybe help us find all the vulnerabilities in that code base.
But people have consistently been unwilling to do that. Like if we were willing to stop adding code we could have stopped decades ago and done SQLite level testing everywhere and probably have found almost all the bugs already.
When we've got people who don't know the difference between ssh and bash creating SaaS companies that generate revenue, yeah there's gonna be a lot of insecure code going out, but that same person can also tell the AI "red team my app to find vulnerabilities and then fix them", and the AI can competently actually do that, I don't know that there will be. I'm not saying that's never going to happen, but the bar is getting raised on both sides.
Plus, the interest and expertise and passion used to favor the red team, attackers. If you wanted to defend against them you had to get on their level, or hire someone on their level. Thats either expensive or requires a time investment that doesn’t make sense for someone who is trying to do much more than just defend against attackers.
Now it’s just as you said- asking AI to red team your app will get you pretty far.