Artificial intelligence can now attack systems on its own: the AI pentester is no longer science fiction. The headlines claim it makes the human pentester obsolete. The research says something more nuanced, and far more useful for anyone who has to defend an organization. We line up the international numbers, and explain what they mean in practice.

✦ Key takeaways
  • AI is powerful, but not magic. AI agents exploit up to 87% of known vulnerabilities when handed a description, but only 13% under realistic conditions.
  • Collaboration is the breakthrough. A team of AI agents is up to 4.3 times more effective than a single agent.
  • It is an arms race. Over $665 million in venture funding, two billion-dollar companies, and an AI platform sitting at the top of the global HackerOne leaderboard.
  • The barrier for attackers is dropping. Known, unpatched vulnerabilities are found and exploited faster than ever.
  • The human remains decisive. The creative, chained attack stays human work, and every AI finding should be verified by a person.

The basics

What is an AI pentester?

An AI pentester, also called an AI pentesting agent, is software that uses a large language model to do the work a human pentester would normally do: reconnaissance, finding vulnerabilities, exploitation and reporting. The word “agent” is the crucial part. A copilot only advises. An agent acts: it reads the output of a command, decides the next step itself, runs it, looks at the result and repeats, until it is in or hits a wall.

That is the difference between ticking off a checklist and thinking a problem through. A classic scanner runs a fixed set of checks and spits out a list. An AI pentester forms a hypothesis, tests it, and tries another approach when it fails. Since 2023, dozens of these agents have appeared, from simple wrappers to full swarms that work together.

What the numbers say

Beyond the hype

Under controlled lab conditions, with a neat description of the vulnerability provided, an AI pentester exploits up to 87% of known vulnerabilities. Impressive, until you take that help away. Against real vulnerabilities, under realistic conditions, the same capability drops to 13%. One study saw a leading model fall from 87% to 7% the moment the description disappeared.

This is the lab-to-reality gap. And it is not a footnote, it is exactly why an automated scan is fundamentally different from an attacker who thinks.

THE LAB-TO-REALITY GAP How often AI actually exploits a vulnerability 87% Lab conditions with a ready-made description 13% Real world no hints, realistic -74 pts
Source: CVE-Bench (ICML 2025) and follow-up research, summarized via AppSec Santa, 2026.

The architecture

One agent is a toy, a swarm is a weapon

The breakthrough is not a smarter model. It is collaboration. Put a single AI pentester on a target and it stalls at the first hurdle. Split the work across a team of specialized agents, with an orchestrator directing them, and effectiveness jumps by a factor of 4.3. That is the measured result of the HPTSA benchmark, not marketing.

ONE AGENT VERSUS A SWARM Single agent AI agent Target system ~13% success Multi-agent swarm Orchestrator Recondiscovery ExploitCVE chains Web / appweb test Target system 4.3x more effective
Source: HPTSA benchmark via AppSec Santa, 2026, shown schematically.

The landscape

2026: from experiment to arms race

This is no longer niche. International research counts more than 39 open-source AI pentesting agents in 2026, and the commercial market is exploding. More than $665 million in venture funding has poured in, with two companies valued above a billion. One AI platform now sits at the top of the global HackerOne leaderboard, with over a thousand validated submissions.

And it is not only startups. In the DARPA AIxCC final, autonomous systems found 86% of the built-in vulnerabilities. Research systems from the big tech companies independently found zero-days in production software that had gone unnoticed for years. The message is unmistakable: tomorrow’s attacker is backed by a machine.

4.3xmore effective with a multi-agent approach
86%detection in the DARPA AIxCC final
#1an AI platform atop HackerOne
$665M+venture funding in AI pentesting

Tomorrow’s attacker is backed by a machine. The question is whether your defense is too.

In practice

What we see at Rootsec in practice

At Rootsec we run AI-driven offensive security not in a demo, but on real engagements. And we deliberately do it on our own, local platform: the AI reasons on our own infrastructure, not in a public cloud. The result is simple but crucial: sensitive client data, discovered vulnerabilities and credentials never leave our environment. For organizations in healthcare and finance, that is often the difference between allowed and not allowed.

Exactly how we set it up we keep to ourselves. But the principle we share gladly, because that is what matters: the machine speeds up reconnaissance and analysis, the human guards quality, and every finding is verified by hand by an experienced pentester before it reaches a report. The AI pentester is an accelerator for us, not a replacement. More coverage in the same time, without giving up depth.

WHERE DOES CLIENT DATA GO? Public AI cloud client network findings credentials leaves the building Local inference own infrastructure findings credentials localmodel nothing leaves the infrastructure
The principle we build on: sensitive engagements run on our own inference, so client data stays in.
Own AI hardware on which Rootsec runs the AI pentester locally and securely
Serious compute under our own roof: this is how we keep the intelligence, and the data, in.

Theory is nice. But the proof is in the results. An example from a recent, authorized engagement:

Case file RS-2026
Authorized · in scope · traceable
Domain Admin. In under 60 minutes.

One signed engagement, one large network. With AI for the reconnaissance and analysis, and a human for the decisive path, our pentesters held the highest rights across the entire domain within the hour: the keys with which a real attacker can do anything.

Target
████████ large organization
Time to Domain Admin
< 60 minutes
Approach
AI-driven, human-led
Verification
manual, by a pentester

The other side

Where the machine fails, the human wins

Back to that 13%. That number is not a weakness of the story, it is the heart of it. An AI is brilliant at ticking off what is known. But the attacks that truly matter, the creative chain where three harmless weaknesses become one disaster, the logic flaw no scanner recognizes, the way in that no one anticipated, that stays human work.

And some attacks only work from the inside. “What can an attacker who is already in do?” No cloud AI answers that for you. For that, a human is on site, with a plan and the right equipment.

Portable Rootsec red team equipment for on-site testing
For the work that only happens from the inside: portable equipment for controlled on-site testing.

The machine does the groundwork. A human turns the key.

Conclusion

What this means for defenders

If you have to protect an organization, the research comes down to three things. One: the barrier for attackers is dropping, because AI makes advanced techniques more widely available. Two: known, unpatched vulnerabilities are now found at speed, so patch discipline and visibility of your own attack surface matter more than ever. Three: a modern pentest should harness the power of the AI pentester, but under human oversight and with your data staying in. Ask your security partner about it specifically.

FAQ

Frequently asked questions

Will AI replace the pentester?

No. The research is clear on this: AI is excellent at known, repeatable work, but fails on the creative, chained attacks that have real impact. AI increases a pentester’s speed and coverage; it does not replace their judgment.

What exactly is an AI pentesting agent?

Software that uses a large language model to independently determine and carry out pentest steps: reconnaissance, finding vulnerabilities, exploitation and reporting. Unlike a scanner, an agent reasons about what it finds and adjusts its approach.

Is AI pentesting safe for my company data?

It depends on how it is set up. Public AI clouds send your data to a third party. Rootsec runs the AI on its own, local platform, so sensitive data does not leave your environment or ours.

How do I know an AI finding is correct?

Through human verification. At Rootsec every finding an AI generates is checked by hand by an experienced pentester before it reaches the report.

Curious what an AI-driven attacker would find at your organization?

In a strategy session we show you what your attack surface looks like today, and what a modern pentest would add. An honest look, not a sales pitch.

Sources

  1. AppSec Santa, The Rise of AI Pentesting Agents: A Technical Analysis (2026).
  2. CVE-Bench (ICML 2025); HPTSA benchmark; DARPA AIxCC final 2026.

Performance figures come from the cited research. The case is our own, authorized engagement; client details are anonymized. Every AI finding is verified by hand by a pentester.