ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

AI and the future of pentesting 

As organisations race to embed AI across their operations, security teams are finding themselves caught in a fundamentally new dynamic.

 

There’s a central paradox where AI is both driving new exposure and being deployed as the solution to it. Businesses are adopting AI tooling at a pace that consistently outstrips the security rigour they’d apply to anything else, writing code that introduces vulnerabilities, spinning up integrations that expand the blast radius of any breach, and doing all this continuously and at machine speed.

 

Traditional security practices like scheduled, fixed-point pentesting have long been unfit for an increasingly fast-paced threat landscape, and the acceleration driven by AI has made their shortcomings too hard to ignore.

 

Yet AI is also part of the answer and will become essential to a continuous approach to pentesting that can provide the ongoing security validation organisations need to match the speed and complexity of modern environments.

 

A new kind of exposure problem

We’re already seeing a wide range of use cases where the addition of AI is starting to break traditional processes. AI coding, for example, can create an endless feedback loop of introducing and finding vulnerabilities. I experimented with this first-hand by building a small web application using AI, then asked the same AI system to audit it. The tool promptly flagged a cross-site scripting vulnerability, which it had introduced itself. AI models like Mythos are accelerating the pace even further and starting to rewrite the rules of finding and managing vulnerabilities. 

 

That loop will increasingly define the security challenge organisations face. As AI-generated code becomes the norm across development teams, AI will be creating attack surfaces and discovering them. The challenge for teams is to implement security workflows to ensure that discovery and remediation keep pace, reducing the window of opportunity for attackers.

 

The risk isn’t limited to code quality, either. After scanning over one million AI tools, we found multiple agentic platforms with fundamental issues like exposure to the internet and a lack of authentication. When AI agent platforms are poorly secured, the consequences reach far beyond the immediate deployment. An exposed agentic workflow doesn’t just reveal a misconfigured tool. It can hand an attacker the credentials, integrations, and capabilities connected to it. Access to the agent often means access to everything behind it.

 

This is a different kind of exposure problem for security teams to manage, piling on both complexity and time pressure. The attack surface isn’t just larger; it’s more dynamic, more deeply integrated, and growing in ways that are increasingly difficult to map.  

 

Existing security strategies weren’t built for this

Vulnerability scanners and pentesting have historically been two of the most valuable approaches to assessing risk, but neither was designed for the environment we’re looking at here.

 

Vulnerability scanners have historically delivered broad and affordable coverage. They can run continuously, but in many cases, they detect without interpreting. This means they’ll tell you something is wrong, but not necessarily if it matters for your specific environment. Additional investigation by security practitioners or engineers has often been necessary. 

 

Pentesting is the opposite, with skilled practitioners providing an in-depth view mirroring that of a real attacker. However, the main barriers to pentesting have been time and cost, meaning that most organisations have had a long window of exposure between tests.

 

While this has been a manageable challenge in the past when exploit windows were longer, it’s no longer tenable in an environment where attackers are rapidly deploying AI-enabled, offensive campaigns. Mean time-to-exploit has collapsed from months to weeks to hours, with projections suggesting it will soon reach minutes. The window between a vulnerability appearing and being weaponised is closing much faster than annual or quarterly pentesting cycles can keep up with.

 

What teams need isn’t more scanning coverage or a bigger pentesting budget, but a framework that moves them towards a continuous, always-on approach to security. 

 

This is where exposure management comes in, combining attack surface monitoring, vulnerability detection, contextual prioritisation, validation of real exploitability, and a clear path to remediation. It’s the operational model that the current environment demands. Introducing AI pentesting agents into the exposure management lifecycle helps enable this at scale by delivering the investigative depth and efficiency that security teams need.

 

The strengths of AI-assisted pentesting

AI provides two powerful improvements to exposure management practices. First, it excels in finding what vulnerability scanners can’t, and the ability to run full pentests more frequently lets security teams run deeper investigations more often. These can be configured to quickly respond to change signals in the environment. 

 

Alongside this, AI also enables a high degree of automation at the critical stages of triage and investigation. False positives have long been a challenge for vulnerability scanners, and this is destined to get worse as the number of vulnerabilities increases. 

 

AI removes these bottlenecks so that teams can respond faster to the threats that really warrant their attention by validating if a vulnerability represents a genuine threat in a specific environment, and prioritising response activity. 

 

For example, AI can correlate a vulnerability on a user’s laptop with that user’s cloud infrastructure permissions - a finding no conventional scanner would surface, because it can’t reason across both layers simultaneously. It can also do something scanners have never managed well: distinguish between findings that genuinely matter and those that don’t. 

 

AI pentesting tools are finding real vulnerabilities - command injection flaws, authentication weaknesses - by reasoning about application context rather than running signature-based checks. Triage, investigation, and validation have typically required a human analyst and hours of work. Agents can now complete that investigation in minutes, meaning stretched teams spend less time on false positives and more time fixing actual problems.

 

A third way forward

Where scanning and pentesting were once very distinct disciplines, that line is blurring. If you remove the human from a penetration test, what you have is a very smart scan. The more interesting question is what sits between the two, and that model is beginning to take shape.

 

Continuous, AI-assisted testing that is more frequent than annual pentests, deeper than daily scans, and triggered on every significant code release is becoming viable as costs come down. 

 

For security teams who are already stretched or overwhelmed, that represents a meaningful shift, not because it removes the need for human oversight, but because it changes where that oversight is focused.

 

For now, the practice of pentesting and its place in security strategies will remain relatively stable, albeit with AI driving more efficiency and cost-reduction. But looking further ahead, as compliance standards evolve, the practice will evolve into a new form of continuous security with the old annual or quarterly pentesting model relegated to a relic of the past. 

 

Keeping pace with this evolution is essential as AI continues generating code and enabling bad actors to operate at speed. The teams that adapt will be those that treat AI security testing as a component of a structured exposure management programme rather than a shortcut around one.

 


 

Chris Wallis is CEO and Founder of Intruder

 

Main image courtesy of iStockPhoto.com and Alena Butusava


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543