Time-to-exploitation has compressed from 2.3 years in 2018 to 1.6 days today, and AI models can now generate working CVE exploits in 10 to 15 minutes for about a dollar. This buyer’s guide replaces the pre-AI SAST evaluation checklist with 10 problems a modern scanner must solve — measurable accuracy, hybrid detection, in-IDE remediation, and AI governance — plus the buyer questions to bring to your next vendor evaluation.