It's... complicated.
AI vulnerability discovery will lead to more secure code in the projects that are using it heavily. Mostly that means the projects that were already taking security very seriously, like operating systems and web browsers. They should get more secure.
Other projects that don't take security seriously will continue to be insecure. The thousands of applications, WordPress plugins, JavaScript libraries, etc. that people blindly install and trust to be secure even though they aren't.
And then there are all the new vibe coded projects that don't even attempt to meet minimum security standards. Those will be trivial to exploit, and the number of them is growing fast. Maybe with time the AI code generation models will get better at creating secure code. Maybe. Right now they're terrible at it.
So some parts of the ecosystem will get more secure, some parts will get less secure, and a year from now everything I just said might not apply anymore. It's all changing fast, and it's really hard to predict.