Fewer than one in ten cybersecurity professionals trust AI testing tools to detect vulnerabilities, and more than three-quarters say their AI vulnerability scanning tools missed critical flaws.


  • Cobalt’s State of Pentesting 2026 report shows that confidence in fully automated AI testing has plummeted, from 29% in 2025 to 9% this year.
  • 78% of respondents found that automated tools ignored critical vulnerabilities; The LLM flaws proved complex, with MTTR dropping from 19 to 36 days and most issues remaining unresolved.
  • Hybrid models have surged to 47% adoption, with experts emphasizing that automation should complement, not replace, elite human expertise in uncovering business logic risks.

As the world praises the Myth and the Chinese rush to create their own variant, a report painting a completely different picture comes from Cobalt.

The cybersecurity company just released the Cobalt State of Pentesting Report 2026, based on two comparative surveys, one in 2025 and one in 2026. By surveying around 450 cybersecurity professionals, Cobalt wanted to see how confident the cybersecurity community is in automated AI vulnerability testing and it turns out it’s not that much.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top