The cybersecurity landscape is accelerating at a pace that would have seemed unthinkable just a few years ago. The number of published common vulnerabilities and exposures (CVEs) surged 263% between 2020 and 2025, while mean time-to-exploit has collapsed, with some projections putting it at minutes by late 2026.
As attackers are moving faster than ever, and exploit windows are shrinking, penetration testing needs to evolve. In the post-Mythos landscape, AI pentesting is providing a much-needed new approach to the challenges stretched security teams face in identifying and remediating vulnerabilities and other risks across their digital estates.
Where the scanning/pentesting distinction is blurring
Security teams have historically worked with two very distinct approaches to assessing risk.
Vulnerability scanners cover a lot of ground cheaply and can run on a continuous basis, but what they cannot do is tell you whether a finding matters in your environment. They detect, but do not interpret.
Penetration testing works differently. A skilled tester gets inside an application, understands how it is built and looks for weaknesses the way an attacker would. The findings tend to be higher quality and better contextualised, but the model has obvious constraints. It is expensive, happens infrequently, and whatever it surfaces reflects a snapshot of the environment at one point in time. A lot can change between tests.
That gap has always been a problem, but it’s become a critical threat in the age of AI. With a growing volume of vulnerabilities and threat actors able to identify and exploit them faster than ever, the old scheduled pentest approach lags dangerously behind. The recent arrival of models like Mythos that can identify huge volumes of flaws at lightning speed has accelerated the issue to breaking point. In the long term the pentest as we know it is set to become a thing of the past.
How pentesting is set to evolve
The question is no longer whether AI will change pentesting, but how completely it will do so. As AI-powered tools become capable of autonomously identifying vulnerabilities at machine speed, the assumptions that have underpinned security testing for decades are coming under pressure.
For now, the pentest report isn’t going anywhere. In the short term the cost and time required to run a pentest will fall, but what it produces still needs to meet established expectations. We are at the beginning of the AI adoption curve, not the end of it. Compliance frameworks move slowly, and auditors expect deliverables that conform to standards built up over many years.
What is changing is the frequency and the trigger for pentesting. Rather than a single substantial engagement each year, the emerging model is one of smaller, more targeted assessments initiated automatically when something in the environment changes, such as when code is shipped, a new service is exposed, or a configuration is modified. The barriers of cost and expertise that made continuous pentesting impractical are eroding and, with them, the case for accepting the gaps that annual testing leaves behind.
This is the direction that pentesting is heading; a transformation into something that runs in the background continuously, surfacing findings as the environment evolves rather than at a fixed point in time.
Providing context and speed by leveraging AI
AI pentesting agents can support the work that human analysts do, particularly with triage, investigation and validation which are the slowest parts of the remediation cycle. For the 42% of midmarket security teams already stretched, overwhelmed or consistently behind, that is time they do not have.
That investigative depth shows up in practice. In our own testing, an AI system correlated a vulnerability on a user’s laptop with that user’s cloud infrastructure permissions, a finding no conventional scanner would have surfaced because it can’t reason across those two layers at the same time. That kind of contextual correlation has not been possible before, and it has a direct impact on how effectively a team can prioritise its workload.
Pentesting agents can investigate a wide range of issues
While AI-powered pentesting is in its infancy, it’s already clear where the model is especially powerful.
When it comes to information disclosure risks, it provides investigative depth that goes further than any scanner. Rather than simply flagging that configuration details or storage buckets are exposed, an AI agent can review what is accessible, evaluate how an attacker might use it and, in some cases, attempt to verify whether exposed credentials are valid.
On injection flaws, an AI agent can reproduce the finding using multiple techniques (error-based, timing-based and UNION-based) to confirm whether an attacker could manipulate the application’s commands or queries to gain unauthorised access.
The difference also shows when it comes to client-side issues such as clickjacking Here, a scanner will flag any page missing the relevant headers, but an AI agent can assess whether the page is actually frameable in a way that poses genuine risk.
These capabilities matter, but the principle of human oversight in all AI deployments still holds true.
The end of pentesting as we know it?
The long-term trajectory points toward continuous testing becoming the default rather than the exception. As the tooling matures and the user base grows, new ways of validating security posture will gain acceptance with auditors, insurers, and compliance bodies. The annual pentest, built on the assumption that depth and frequency are mutually exclusive, will look increasingly like a product of its time.
Getting there will require the industry to resolve some genuinely difficult questions. Demonstrating the rigour of a continuous programme to an auditor is a different challenge to presenting a point-in-time report. The signals that should trigger an automated assessment, the liability implications for insurers, and the appropriate degree of AI autonomy versus human control are all areas where standards and expectations are still forming.
Teams adopting AI security testing today are operating ahead of that settled framework. Going in with clear criteria and a defined approach to oversight is essential, not because the tools aren’t capable, but because the context in which they operate is still evolving. The case for AI pentesting is well established. The work now is in building the programmes around it that will stand up to scrutiny.
Learn more at intruder.io
- Cybersecurity
- Digital Strategy






























































































































