Why penetration testing is moving from a point-in-time engagement to a persistent security function
Earlier this year, in Continuity Was Always the Point, I argued that cybersecurity had outgrown the idea of periodic assessment. The reason was simple: our environments are no longer periodic. Infrastructure, identities, applications and cloud resources change constantly, while new vulnerabilities arrive on a schedule that has nothing to do with annual testing. A program built around snapshots will always spend some of its time describing an environment that’s already moved on.
Continuity was the necessary response, but it exposed another bottleneck. Even when security technology runs continuously, people still have to operate it. Someone initiates the test, interprets the output, separates noise from real findings, connects weaknesses into attack paths, tracks remediation, retests and briefs leadership. For a stretched security team, continuous tooling can become continuous work.
We made the tools continuous. We did not make the work continuous.
That gap is where agentic security, and agentic penetration testing in particular, becomes interesting. The operating model changes when a practitioner can delegate defined security work to an agent, with scope, evidence and human authority around it, rather than personally driving every tool and every step. That’s a much larger shift than simply adding AI to a penetration-testing product.
How AI is accelerating the attack surface
AI is accelerating the rate at which companies build and connect things. Developers can stand up applications in hours, teams can connect services quickly, and small groups can automate work that once demanded far more people. I think that’s exciting. The security problem begins when that velocity lands on top of fundamentals that were never finished.
Take an organization with incomplete asset management, weak vulnerability management, inconsistent patching, poorly understood identity controls and perhaps one penetration test every year. Add AI-generated code, new APIs, cloud infrastructure, service accounts, tokens, integrations and autonomous agents that need access to applications and data. The old attack surface remains, with more relationships, permissions and code paths layered on top.
The agents themselves also become part of the security model. An agent can carry an identity, credentials and permissions, and may be able to call tools or act on internal systems. NIST is already examining agent identity and authorization in its February 2026 concept paper on the identity and authority of software agents, because useful agents need controlled access to applications and data. The OWASP Top 10 for Agentic Applications for 2026 raises the same class of concerns around tool misuse, identity and privilege abuse, and supply-chain weaknesses.
None of this means organizations should slow AI adoption. They should match adoption speed with the ability to understand what changed, what’s exposed and what can actually be exploited. Otherwise, organizations compound new technology on top of old security debt.
A Monday assessment describes Monday: why point-in-time pentests go stale
Any security assessment is better than no assessment. Annual penetration tests, vulnerability scans, source-code reviews and red-team exercises all provide value, especially for organizations still building a baseline. The assessment itself isn’t the problem. The problem is the assumption that its conclusions remain current after the environment changes.
THE STALENESS PROBLEM Monday: the penetration test concludes. Tuesday: a critical vulnerability is disclosed. Wednesday: attackers begin targeting it. Thursday: an engineer exposes a new service while solving a production problem. Friday: a developer ships a new AI-assisted API endpoint. Nothing about Monday’s report was necessarily wrong. The environment simply stopped being Monday’s environment. |
Vulnerability disclosure makes the problem even clearer. Palo Alto Networks published its security advisory for CVE-2024-3400 on April 12, 2024, a critical PAN-OS command-injection vulnerability that was being exploited in the wild. Initial fixed releases arrived on April 14. That’s a fast vendor response, but a patch existing two days later doesn’t mean an enterprise is fixed. Teams still have to identify affected systems, deploy the update, investigate possible compromise and verify remediation.
The 2026 Verizon Data Breach Investigations Report (DBIR) shows how wide that gap can become. Vulnerability exploitation is now the leading known initial-access vector in its dataset, accounting for 31% of breaches. For CISA Known Exploited Vulnerabilities observed in participating organizations, only 26% were fully remediated, and the median time to full remediation reached 43 days. Attackers don’t wait that long, which is why a periodic view of exposure is increasingly inadequate.
Continuous awareness solves part of that timing problem. It doesn’t solve the human capacity problem that comes after discovery.
From security tools to delegated responsibility
Consider the CISO walking into the office at 8:30 in the morning, assuming they slept at all. They shouldn’t have to open six dashboards and wait for someone to correlate the results before they understand what changed overnight. They should be able to ask, “What happened while I was away?” and get an answer that shapes the day.
EXAMPLE MORNING BRIEF Three externally exposed assets changed overnight. Two were expected. I reviewed the third and did not identify a validated path into production. A critical vulnerability disclosed overnight may affect fourteen internal systems. Nine are isolated from sensitive environments, four are scheduled for remediation, and one sits on a possible path to a sensitive system. I stopped before validating that path because exploitation requires your approval. Two findings from last week were remediated and passed retesting. One remains overdue. I recommend we address that item first. |
That morning brief is the difference between a tool and delegated responsibility. The agent understands its assigned environment, performs the work it’s authorized to perform, maintains context from prior testing, and escalates the decisions that still belong to a human. The practitioner gets an explanation of what changed, what matters and what needs a decision, rather than another raw feed of alerts.
Security teams do not need another tool that creates another queue. They need help closing the one they already have.
What makes an AI penetration testing agent useful?
It’s tempting to look at increasingly capable models and conclude that the penetration tester has already been automated. I don’t believe that’s true, and we’ve written before about why the future of pentesting isn’t a scanner or a human working alone. Today’s models can perform reconnaissance, interpret vulnerability information, operate tools and complete portions of attack chains. Under the right conditions, the results can be impressive, but they’re still uneven.
A February 2026 study, What Makes a Good LLM Agent for Real-world Penetration Testing?, analyzed 28 LLM-based penetration-testing systems. It found that some failures can be addressed through better tooling and prompts, while harder problems around planning, state management and longer attack chains persist. The same research demonstrated something practitioners should pay attention to: improving the system around the model materially improves performance.
The model is not the pentester.
The actual capability comes from the model plus the harness around it: tools, methodology, memory, evidence, scope, rules of engagement and the expertise encoded into the system. A seasoned assessor knows the highest severity score isn’t always the finding that matters most. A modest configuration weakness can become critical when combined with a credential or identity relationship elsewhere in the environment.
That judgment comes from methodology and experience. Giving a model access to a scanner and a shell doesn’t give it the operating knowledge of someone who’s spent years breaking into networks. The gap is narrowing, but effective security agents will still depend on the quality of the knowledge, tools and decision framework around the model.
Specialization and bounded authority: rules of engagement for AI agents
That’s also why specialization matters. There’s no one human security engineer who’s equally strong at external infrastructure, Active Directory, cloud, web applications, APIs and source code. Each domain has its own failure modes, tools and instincts. An agent responsible for those environments should reflect the same reality.
The logical model is specialization under a common authority. External agents focus on reconnaissance and internet-facing infrastructure. Internal agents focus on identity, Active Directory, segmentation and lateral movement. Cloud, application/API and source-code agents bring their own knowledge and tools. The practitioner sets the objective and scope, while specialized agents work within their domains and return evidence to a coordinating authority.
Capability is not authorization.
A SIMPLE RULE OF ENGAGEMENT Perform discovery. Assess Active Directory. Identify configuration weaknesses. Do not exploit findings without explicit authorization. If validation requires crossing that boundary, stop, preserve the evidence and ask for a decision. |
A useful penetration-testing agent will eventually be capable of actions we shouldn’t always permit. Rules of engagement need to be enforced as part of the system, not left as polite instructions in a prompt. That applies especially to destructive techniques, sensitive production systems, persistence, data access and anything capable of interrupting business operations.
Penetration testers have always had rules of engagement because humans make mistakes too. Agentic testing should inherit that discipline and make it enforceable through identity, authorization, auditability, scope and stop conditions.
Assume initial access. Harden what comes next.
Some attacks are inevitable. Third parties and supply chains get compromised, credentials get stolen, insiders exist and zero-days exist. The 2026 Verizon DBIR reports third-party involvement in 48% of breaches, which is a useful reminder that an organization can’t control every participant in its ecosystem or every vulnerability its vendors will discover tomorrow.
What an organization can control is how difficult its own environment is to traverse. As a former adversary, this is the part that matters to me. Suppose an attacker has a zero-day that gets through the perimeter. The important question is what that foothold buys the attacker next.
Now the attacker has to deal with the internal environment. Are access-control lists tight, SMB shares controlled, Active Directory Certificate Services configurations cleaned up and service accounts protected from easy Kerberoasting? Can one compromised identity reach sensitive systems, does a cloud role carry excess privilege, or does a custom API provide a path toward isolated data? These conditions determine whether initial access becomes a breach with a large blast radius.
This is why organizations need to continuously harden external-facing assets, on-premises and hybrid corporate networks, cloud environments, proprietary applications and APIs, and source code, including the growing volume created with AI assistance. Those surfaces are the paths toward the crown jewels: customer information, financial data, intellectual property and production infrastructure.
If those paths are repeatedly assessed and hardened, the attacker has to spend more time and burn more capability to move. They may need another vulnerability, another credential or a noisier technique, and each additional step creates another opportunity for EDR, SIEM, identity controls, network monitoring or a human defender to detect what’s happening. You may not prevent every compromise, but you can dramatically reduce what an attacker can accomplish after one.
Findings are not the outcome: how to measure security progress
There’s one thing AI won’t solve for us: organizations still have to fix things. An agent can find vulnerabilities faster, investigate them, reduce false positives, identify attack paths, prioritize what matters, create remediation guidance, follow up with owners and retest fixes. If nobody acts on that work, we’ve simply automated the discovery of security debt.
That changes how these systems should be measured. Finding count is a poor proxy for security progress. Measure the time from exposure to understanding, from understanding to validation, from validation to a decision, from decision to remediation, and from remediation to proof that the problem is actually gone.
Continuous exposure management reduces uncertainty. Agency should reduce the human effort required to act on that understanding. For overworked, budget-conscious security teams, the practical value is having more of the security workflow move forward without adding another analyst to every step.
Agency is next
I’m cautious about making predictions about cybersecurity. We’ve been promised revolutions before, and current autonomous pentesting systems still have real limitations. Human researchers, red teams and experienced practitioners will remain essential anywhere creativity, ambiguity, consequences and accountability matter.
Still, the direction of travel is difficult to ignore. Organizations are creating technology faster, their attack surfaces are more dynamic, attackers are moving faster, and security teams remain constrained by people, time and budget. At the same time, AI systems are getting better at reasoning over security information, operating tools, maintaining context and following bounded workflows.
Put those trends together and the operating model starts to change. Penetration testing began as an engagement and is becoming a continuous capability. The next step is a persistent security function in which organizations can delegate defined areas of responsibility to specialized agents while practitioners retain authority, judgment and accountability.
The systems that matter will do more than give practitioners another AI-powered interface. They’ll take responsibility for work practitioners handle manually today: watching for change, testing within scope, validating evidence, following remediation, retesting and escalating decisions that require a human. The practitioner remains in charge, but spends more time supervising outcomes and less time operating individual tools.
Continuity was the point. Agency is next.
What is agentic penetration testing?
Agentic penetration testing uses specialized AI agents to carry out defined security testing work, such as discovery, assessment, validation and retesting, inside a scope and rules of engagement set by a human practitioner. The practitioner keeps authority over high-impact decisions like exploitation, while the agents handle the ongoing operational work.
How is agentic penetration testing different from continuous penetration testing?
Continuous testing keeps security tools running so findings stay current. Agentic testing goes a step further and delegates the work around those tools, including triage, attack path analysis, remediation follow-up and retesting, to agents that escalate decisions a human needs to make.
Will AI agents replace human penetration testers?
Not today. A February 2026 study of 28 LLM-based penetration-testing systems found that planning, state management and long attack chains remain hard problems for agents. Human researchers and red teams stay essential wherever creativity, ambiguity and accountability matter.
How do you keep AI pentesting agents within scope?
Enforce rules of engagement as part of the system through identity, authorization, auditability, scope and stop conditions. For example, an agent can assess Active Directory and identify weaknesses, then stop, preserve the evidence and request approval before exploiting anything.
How should organizations measure AI-driven security testing?
Track the time between each stage: exposure, understanding, validation, decision, remediation and a verified retest. Finding counts alone don’t show whether an organization is getting more secure.
About the Author
Hector Monsegur is Chief Research Officer and co-founder of SafeHill. A former adversary who now helps organizations defend against the techniques he once used, he co-hosts Hacker & the Fed with former FBI Special Agent Chris Tarbell.