An avalanche of reports (both good and bad quality) had strained existing processes and teams. On the other hand, improved tooling also helped defenders do better internal research and speed up patching, among other processes.
Overall, security research might be better with AI tooling, but we also need to throw more humans at the problem. And pay them well.
Recent trends are generally good for users (better security, hopefully). But it's bleak for security researchers who focus on bug bounties, myself included.
I can probably no longer make decent income from VRPs. I don't know how many others can too, given the widespread suspension of VRPs or narrower scopes of higher-difficulty issues (~good) with historically-low rewards (awful). While I had seen this coming for a year or so, it's still disappointing.