Report by Cobalt
AI and Pentesting Pulse Report 2026
Key Findings
47% of organizations favor automation for low-risk environments, up 22 percentage points.
60% of security professionals state they require stronger LLM testing capabilities.
42% of security professionals plan to increase human-led red team operations.
The meantime to resolve (MTTR) for AI/LLM security issues is 36 days, up from 19 days in 2025.
Support for hybrid testing models increased by 22 percentage points to 47%.
78% of organizations experienced fully automated scanning tools missing critical vulnerabilities and returning false negatives.
77% of organizations conduct regular security assessments and pentests for AI-powered products, an increase of 11 percentage points from last year.
Among organizations with confirmed AI-related security incidents, Shadow AI contributed to 44% of incidents, data or model poisoning 41%, improper output handling 41%, supply chain vulnerabilities 35%, and prompt injection 34%.
9% of organizations rely entirely on AI automation for testing, down from 29%, while 47% prefer a hybrid testing model.
82% of security professionals report that their teams are dedicating significantly more effort into AI security initiatives.
32% of AI-related pentest findings were classified as high risk, compared to 12% of all pentest findings overall.
38% of LLM vulnerabilities were fixed while 62% remain open.