An AI security tool can be worse than useless if it floods engineers with vulnerabilities that sound convincing but cannot actually be exploited. Google's PageBreak project is built around that problem. The agent is allowed to generate hypotheses broadly, but a separate validator has to execute a real payload against a running environment before the finding becomes a report.1

IN BRIEF

Google says its internal PageBreak agent found more than 500 cross-site scripting vulnerabilities in first-party web applications. The important design choice was not the model alone: candidate bugs are passed to non-AI-written validators that execute a real payload. Only verified exploits are reported, which Google says produces a near-zero false-positive rate on that validated path.1, 2

What Google reports from PageBreak. XSS vulnerabilities: 500+ — Google-reported findings across first-party web applications after PageBreak was run at large scale.. False positives: Near-zero — Google's description of reports that make it through the deterministic validation path.. Full project: Jan. 2026 — PageBreak moved from a November 2025 pilot to a full project in January 2026.. Values and their context are also available as HTML below.
What Google reports from PageBreak. Values and their context are also available as HTML below.1

What Google reports from PageBreak

500+
XSS vulnerabilities1

Google-reported findings across first-party web applications after PageBreak was run at large scale.

Near-zero
False positives1

Google's description of reports that make it through the deterministic validation path.

Jan. 2026
Full project1

PageBreak moved from a November 2025 pilot to a full project in January 2026.

The model proposes. The validator has to prove it

Google says PageBreak can use different models, with most usage based on Gemini models. When the agent identifies a possible flaw, it hands the hypothesis to a specialized validator written without AI. That validator executes a real payload. A report reaches a product team only when the exploit is reproduced.1

PageBreak separates discovery from proof1
StageWhat happensEvidence standard
SearchThe AI agent explores code and running applications for potential vulnerabilities.A plausible hypothesis is enough to continue.
ValidationA specialized deterministic validator executes a real payload.The suspected exploit must reproduce.
ReportingVerified findings are sent to product teams.Google says unverified hypotheses are withheld.
LearningFailed hypotheses can inform future searches.A failed validator does not become a vulnerability report.

Why XSS is a good test of the idea

Cross-site scripting, or XSS, lets malicious content execute in a user's browser when untrusted input reaches a page unsafely. OWASP notes that successful XSS can expose sensitive information, alter page content or impersonate users. That makes exploitability a concrete property a validator can test rather than a purely stylistic code concern.2

Near-zero false positives is not the same as complete coverage

The strongest caveat is also in Google's own description. Validators only prove vulnerability classes they know how to test. If validation coverage is incomplete, the system can miss real bugs. Low false positives answer the question 'Are reported findings real?' They do not answer 'Did the system find every real vulnerability?'1

The broader agent-design lesson

  • Let a probabilistic model search a large possibility space.
  • Use a deterministic or externally checkable step for claims that can be proved.
  • Escalate only after the verification step succeeds.
  • Track false negatives separately from false positives.

That pattern is useful beyond cybersecurity. S&C's agent-success guide asks what counts as a completed task. PageBreak is a concrete example: a compelling vulnerability hypothesis is not success. Reproducing the exploit is.

The interesting part of PageBreak is therefore not that an AI can think like a security researcher. It is that Google designed a second system that can say no. As agents take on more consequential work, verification layers may matter as much as the models generating the work in the first place.

Sources and methodology

Sources checked September 28, 2026. Dates and periods for individual figures are stated beside them.

  1. Google: Agentic Hacks, Real Proofs — Inside PageBreak ↗Accessed 2026-09-28
  2. OWASP: Cross Site Scripting Prevention Cheat Sheet ↗Accessed 2026-09-28
Scope and assumptions

The 500+ findings and near-zero false-positive characterization are Google-reported results from Google's own internal environment.

Validator coverage is incomplete, so low false positives do not establish low false negatives or complete vulnerability coverage.

The article explains defensive security architecture and does not provide exploitation instructions.

Continue reading

Unit 42 Says New CVEs Can Be Weaponized in 15 Minutes. Cybersecurity Is Becoming AI vs. AI →

86% Agreement Can Still Miss Half the AI Failures →

Meta’s AI Can Send Emails and Make Purchases. What Should You Let It Touch? →