Why the Industry Is Both Racing Toward Autonomous, and Pulling Back From It

Today, we launched Cobalt Autonomous Pentest, a new offering that delivers fast, actionable pentests with findings in just 24 hours, directed by the elite Cobalt pentesters our customers already rely on. It’s another step forward in our mission to lead the market in continuous offensive security.

This product launch is informed by conversations we have had with security leaders in nearly every industry, including a recent session with our customer advisory board (CAB). In almost every conversation, two common themes emerge:

Security leaders are racing to scale. Attackers are leveraging AI to strike continuously while DevOps pipelines ship code faster than security teams can validate. Periodic annual testing is simply no longer an option.

The benefit of using AI for offensive security is clear, but security leaders are not ready to trust AI blindly. They require strict guardrails.

Nine out of 10 of the customers at our CAB said attacker speed is the primary driver for pursuing autonomous pentesting. Every single one of them emphasized that human expertise in overseeing the use of AI is non negotiable. They want the best of both worlds: the speed of AI to cover an expanding attack surface and humans to hold ultimate accountability for how tests are conducted and validated.

This week’s news on OpenAI’s models escaping a sandboxed testing environment and exploiting a vulnerability to gain access to Hugging Face’s systems is proof that security leaders' fears are rooted in reality. According to Hugging Face, the incident is unique because it was “driven, end to end, by an autonomous AI agent system.”

That is why we build automation into our platform where it fits best, while reserving human intelligence for where it matters most. Purely manual pentesting is a thing of the past—everything we do today is AI-assisted. However, experienced pentesters still supply critical context: validating whether a weakness is genuinely exploitable and measuring its potential impact against a company’s specific IT stack and risk tolerance.

Why Autonomous Pentesting Can’t Wait

AI acts as a force multiplier on both sides of the fight. Adversaries use models to attack at machine speed, while engineering teams use AI tools to ship code faster than ever. To meet today's threat landscape, enterprises must shift from compliance-driven assessment schedules to continuous, risk-based offensive security programs.

Gartner© echoed this shift in a clear prediction on the future of offensive security:

According to Gartner: "By 2028, over 60% of enterprise pen test programs will operate as continuous validation executed within DevSecOps pipelines and governed by CTEM, replacing annual assessments as the primary proof of resilience."

Our own data from 5,000 annual pentests shows exactly this programmatic approach is superior. Our top-performing customers close vulnerabilities 4.5x faster than the low-performing ones.

The Foundation for Continuous Offensive Security

Continuous offensive security is no longer optional. Cobalt Autonomous Pentest is the foundation that makes it possible. AI agents, built on the industry's largest dataset of real world pentest results, and directed by elite Cobalt pentesters, deliver fast pentests that help you reduce your risk.

By combining Cobalt Autonomous Pentest with our elite testers, red teaming, DAST, and attack surface monitoring—all built on the Cobalt Offensive Security Platform—we provide organizations a holistic program that continuously validates risk —with the flexibility to adapt as business priorities shift.

Key capabilities include:

  • Expert Oversight: Elite Cobalt pentesters direct every pentest, ensuring the AI operates strictly within your program’s boundaries.
  • Model agnostic architecture: An AI engine built to adapt seamlessly as frontier models evolve.
  • 24 Hour Findings Delivery: Actionable insights delivered within a single day, so your team starts the next day with full visibility into their exposure.

Three Pillars of Modern Offensive Security

We believe a successful continuous offensive security program requires three essential components—no single element is sufficient on its own:

  1. AI Automation for speed and scale
  2. Human Expertise to provide creative adversary thinking and guardrails.
  3. A Unified Platform to manage workflows, drive remediation, and provide the flexibility to meet individual customer needs.

Cobalt combines these three pillars to continuously identify, prioritize, and remediate exploitable risk with the speed, flexibility, and precision modern security teams demand.

The Future of Pentesting Is Being Written Today

The security leaders in our CAB were clear. They want the speed AI makes possible and the accountability only expert humans provide. They should not have to choose. Cobalt Autonomous Pentest is how we deliver both, and it is the foundation of a continuous offensive security program that validates real risk across the full attack surface.

We pioneered pentesting as a service (PTaaS) to bring speed and transparency to a slow, siloed industry. Today, we are again reinventing offensive security as the attack surface expands across cloud infrastructure, APIs, and AI-powered applications.

The future of this market is human-led and AI-powered - and we are building that foundation today.

Come see Cobalt Autonomous Pentest in action at Black Hat USA, booth 4903. Or schedule a demo with our team today.

 

Back to Blog
About Sonali Shah
Sonal Shah joined Cobalt as CEO in August 2024. She joined us after serving on the company’s Board of Directors. She is a seasoned business leader and product visionary with more than 20 years of experience scaling high-growth businesses across the cybersecurity landscape. Shah holds an MBA from Wharton and a Masters in Economics from the London School of Economics. More By Sonali Shah