Report by Cobalt

AI and Pentesting Pulse Report 2026

12 FINDINGSPublished Jun 25, 2026
View Original Report →

Key Findings

47% of organizations favor automation for low-risk environments, up 22 percentage points.

Risk ManagementAutomationTestingOffensive Security

60% of security professionals state they require stronger LLM testing capabilities.

AI SecurityLLM TestingOffensive Security

42% of security professionals plan to increase human-led red team operations.

Red TeamingOffensive SecurityAI Security

The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.

Incident ResponseAI SecurityMTTRLLM Security

Support for hybrid testing models increased by 22 percentage points to 47%.

Hybrid TestingOffensive Security

78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.

Vulnerability ManagementFalse NegativesAutomationOffensive Security

77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.

Pen TestingAI SecuritySecurity AssessmentsOffensive Security

Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.

AI SecurityAttack VectorsSupply ChainShadow AI

9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.

AI TestingHybrid TestingOffensive Security

82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.

AI Security

32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.

Pen TestingAI SecurityRisk ClassificationOffensive Security

38% of LLM vulnerabilities were fixed while 62% remain open.

AI SecurityVulnerability ManagementLLM VulnerabilitiesOffensive Security