Artificial intelligence can now attack systems on its own: the AI pentester is no longer science fiction. The headlines claim it makes the human pentester obsolete. The research says something more nuanced, and far more useful for anyone who has to defend an organization. We line up the international numbers, and explain what they mean in practice.
- AI is powerful, but not magic. AI agents exploit up to 87% of known vulnerabilities when handed a description, but only 13% under realistic conditions.
- Collaboration is the breakthrough. A team of AI agents is up to 4.3 times more effective than a single agent.
- It is an arms race. Over $665 million in venture funding, two billion-dollar companies, and an AI platform sitting at the top of the global HackerOne leaderboard.
- The barrier for attackers is dropping. Known, unpatched vulnerabilities are found and exploited faster than ever.
- The human remains decisive. The creative, chained attack stays human work, and every AI finding should be verified by a person.
The basics
What is an AI pentester?
An AI pentester, also called an AI pentesting agent, is software that uses a large language model to do the work a human pentester would normally do: reconnaissance, finding vulnerabilities, exploitation and reporting. The word “agent” is the crucial part. A copilot only advises. An agent acts: it reads the output of a command, decides the next step itself, runs it, looks at the result and repeats, until it is in or hits a wall.
That is the difference between ticking off a checklist and thinking a problem through. A classic scanner runs a fixed set of checks and spits out a list. An AI pentester forms a hypothesis, tests it, and tries another approach when it fails. Since 2023, dozens of these agents have appeared, from simple wrappers to full swarms that work together.
What the numbers say
Beyond the hype
Under controlled lab conditions, with a neat description of the vulnerability provided, an AI pentester exploits up to 87% of known vulnerabilities. Impressive, until you take that help away. Against real vulnerabilities, under realistic conditions, the same capability drops to 13%. One study saw a leading model fall from 87% to 7% the moment the description disappeared.
This is the lab-to-reality gap. And it is not a footnote, it is exactly why an automated scan is fundamentally different from an attacker who thinks.
The architecture
One agent is a toy, a swarm is a weapon
The breakthrough is not a smarter model. It is collaboration. Put a single AI pentester on a target and it stalls at the first hurdle. Split the work across a team of specialized agents, with an orchestrator directing them, and effectiveness jumps by a factor of 4.3. That is the measured result of the HPTSA benchmark, not marketing.
The landscape
2026: from experiment to arms race
This is no longer niche. International research counts more than 39 open-source AI pentesting agents in 2026, and the commercial market is exploding. More than $665 million in venture funding has poured in, with two companies valued above a billion. One AI platform now sits at the top of the global HackerOne leaderboard, with over a thousand validated submissions.
And it is not only startups. In the DARPA AIxCC final, autonomous systems found 86% of the built-in vulnerabilities. Research systems from the big tech companies independently found zero-days in production software that had gone unnoticed for years. The message is unmistakable: tomorrow’s attacker is backed by a machine.
Tomorrow’s attacker is backed by a machine. The question is whether your defense is too.
In practice
What we see at Rootsec in practice
At Rootsec we run AI-driven offensive security not in a demo, but on real engagements. And we deliberately do it on our own, local platform: the AI reasons on our own infrastructure, not in a public cloud. The result is simple but crucial: sensitive client data, discovered vulnerabilities and credentials never leave our environment. For organizations in healthcare and finance, that is often the difference between allowed and not allowed.
Exactly how we set it up we keep to ourselves. But the principle we share gladly, because that is what matters: the machine speeds up reconnaissance and analysis, the human guards quality, and every finding is verified by hand by an experienced pentester before it reaches a report. The AI pentester is an accelerator for us, not a replacement. More coverage in the same time, without giving up depth.

Theory is nice. But the proof is in the results. An example from a recent, authorized engagement:
Authorized · in scope · traceable
One signed engagement, one large network. With AI for the reconnaissance and analysis, and a human for the decisive path, our pentesters held the highest rights across the entire domain within the hour: the keys with which a real attacker can do anything.
- Target
- ████████ large organization
- Time to Domain Admin
- < 60 minutes
- Approach
- AI-driven, human-led
- Verification
- manual, by a pentester
The other side
Where the machine fails, the human wins
Back to that 13%. That number is not a weakness of the story, it is the heart of it. An AI is brilliant at ticking off what is known. But the attacks that truly matter, the creative chain where three harmless weaknesses become one disaster, the logic flaw no scanner recognizes, the way in that no one anticipated, that stays human work.
And some attacks only work from the inside. “What can an attacker who is already in do?” No cloud AI answers that for you. For that, a human is on site, with a plan and the right equipment.

The machine does the groundwork. A human turns the key.
Conclusion
What this means for defenders
If you have to protect an organization, the research comes down to three things. One: the barrier for attackers is dropping, because AI makes advanced techniques more widely available. Two: known, unpatched vulnerabilities are now found at speed, so patch discipline and visibility of your own attack surface matter more than ever. Three: a modern pentest should harness the power of the AI pentester, but under human oversight and with your data staying in. Ask your security partner about it specifically.
FAQ
Frequently asked questions
Will AI replace the pentester?
No. The research is clear on this: AI is excellent at known, repeatable work, but fails on the creative, chained attacks that have real impact. AI increases a pentester’s speed and coverage; it does not replace their judgment.
What exactly is an AI pentesting agent?
Software that uses a large language model to independently determine and carry out pentest steps: reconnaissance, finding vulnerabilities, exploitation and reporting. Unlike a scanner, an agent reasons about what it finds and adjusts its approach.
Is AI pentesting safe for my company data?
It depends on how it is set up. Public AI clouds send your data to a third party. Rootsec runs the AI on its own, local platform, so sensitive data does not leave your environment or ours.
How do I know an AI finding is correct?
Through human verification. At Rootsec every finding an AI generates is checked by hand by an experienced pentester before it reaches the report.
Curious what an AI-driven attacker would find at your organization?
In a strategy session we show you what your attack surface looks like today, and what a modern pentest would add. An honest look, not a sales pitch.
Sources
- AppSec Santa, The Rise of AI Pentesting Agents: A Technical Analysis (2026).
- CVE-Bench (ICML 2025); HPTSA benchmark; DARPA AIxCC final 2026.
Performance figures come from the cited research. The case is our own, authorized engagement; client details are anonymized. Every AI finding is verified by hand by a pentester.