Google disclosed on September 24 that its Product Security team developed PageBreak, an internal autonomous AI agent designed to identify exploitable vulnerabilities in first-party web applications. Operating as a fully-fledged project since January 2026 after a November 2025 pilot, PageBreak has uncovered more than 500 cross-site scripting (XSS) flaws. Unlike conventional AI scanners that often generate high volumes of false positives, PageBreak employs a specialized validator built on Google's Gemini models to confirm each hypothesis by executing a working exploit against a live copy of the application. This methodology results in a near-zero false-positive rate, addressing the industry-wide challenge of distinguishing genuine security holes from AI-generated hallucinations.

The system highlights the efficacy of structural security measures; when tested against applications built on Google's newer "high-assurance" web frameworks, which are designed to make specific bug classes structurally impossible, PageBreak identified only two vulnerabilities. This contrasts sharply with the hundreds found in legacy systems, reinforcing the value of secure-by-design architecture over post-hoc patching. Google notes that PageBreak leverages unique internal advantages, including a unified code repository spanning billions of lines and established scanning infrastructure, making the approach difficult for smaller entities to replicate. The company plans to integrate PageBreak with CodeMender, an automated bug-fixing agent, to provide proposed patches alongside confirmed vulnerability reports.