Chrome's AI vulnerability pipeline shows why security teams should measure verified, shipped, and installed fixes instead of counting discovered bugs.