Less than one in ten cybersecurity professionals trust AI testing tools to find vulnerabilities, and over three quarters say their AI vulnerability scanning tools missed critical bugs


  • Cobalt’s 2026 State of Pentesting report shows confidence in fully automated AI testing collapsed from 29% in 2025 to 9% this year
  • 78% of respondents saw that automated tools miss critical vulnerabilities; LLM failures proved to be complex, with MTTR increasing from 19 to 36 days, and most issues remaining unresolved
  • Hybrid models rise to 47% adoption as experts emphasize automation must complement, not replace, elite human expertise in uncovering business logic risks

While the world praises the Mythos and the Chinese rush to create their own variant, a report that paints a completely different picture comes from Cobalt.

The cybersecurity firm just released the Cobalt State of Pentesting Report 2026, based on two comparative studies, one in 2025 and one in 2026. Polling about 450 cybersecurity professionals, Cobalt wanted to see how confident the cybersecurity community is in automated AI testing—and not so many vulnerabilities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top