I think an argument can be made that some software has gotten more secure.
I don’t think it can be denied that the models do show an ability to find security vulnerabilities that may have otherwise been missed