By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: FireCompassPublished December 17, 2025

TL;DR: AI is pushing pentesting, red teaming, and vulnerability discovery toward continuous, event-triggered, machine-speed execution, according to FireCompass, while Bruce Schneier and Bikash Barai argue that the real shift is from human cadence to self-modifying security workflows. The implication is that attack-surface validation, contextual reasoning, and remediation loops now need to be governed as a programme, not a quarterly exercise.


At a glance

What this is: This fireside chat argues that AI is reshaping offensive security by making pentesting faster, broader, and more continuous.

Why it matters: It matters to IAM and broader security teams because machine-speed offensive testing changes how quickly exposed access paths, credentials, and privilege paths can be found and abused.

By the numbers:

👉 Read FireCompass's analysis of AI-driven offensive security and continuous pentesting


Context

AI-driven offensive security is challenging a model that still assumes attackers move at human speed and defenders can validate risk on a quarterly cadence. In practice, continuous attack-path discovery and rapid exploitation attempts expose how much of today’s security assurance depends on timing, not just control design.

For IAM, PAM, and NHI programmes, the key issue is not whether AI can replace a human tester, but whether security workflows can keep up with machine-speed discovery of exposed access, over-privilege, and stale credentials. The current model is increasingly misaligned with how fast modern attack surfaces change.


Key questions

Q: How should security teams adapt pentesting programs for AI-enabled adversaries and continuous attack surfaces?

A: Security teams should move from periodic, point-in-time testing to continuous validation across the full environment. AI-enabled attackers can probe and chain weaknesses faster than traditional testing cycles allow. A workable programme combines automated breadth with human validation for depth, so teams can confirm what is actually exploitable, prioritise remediation, and reduce blind spots before adversaries reach the same assets.

Q: Why do annual pentests fail to catch modern application risk?

A: Annual pentests assume the attack surface stays stable long enough for a point-in-time review to remain valid. That breaks in high-release environments because authorization bugs, secret-handling mistakes, and business logic flaws can appear and disappear between test cycles. Continuous delivery needs continuous confirmation, otherwise the organisation is only testing yesterday's system.

Q: What should teams do when AI finds attack paths faster than remediation can keep up?

A: They should use exposure-driven prioritisation, with identity and privilege issues at the top of the queue. High-value fixes are the ones that remove reusable access, collapse excess privilege, or cut off multi-step compromise paths. If remediation lags discovery, backlog becomes a measurable control failure, not just an operational inconvenience.

Q: How can organisations keep AI offensive testing accurate and useful?

A: They need high-quality context around assets, identities, and dependencies so AI does not just generate noise. Accurate inventories, access relationships, and ownership data let automation distinguish true risk from irrelevant findings. Without that context, AI scales uncertainty instead of assurance.


Technical breakdown

Machine-speed attack discovery and execution

AI changes offensive security by compressing reconnaissance, validation, and exploitation into a much shorter loop. In manual testing, each step depends on human attention, time, and prioritisation. AI systems can run many attempts in parallel, adapt to partial results, and chain observations into follow-on actions. That shifts offensive security from a bounded engagement to a continuous process that can revisit targets as the environment changes. For defenders, the implication is that exposures are no longer evaluated only at test time. They can be discovered, re-tested, and exploited within the same operational window.

Practical implication: shift from periodic validation to continuous exposure testing across identity, cloud, and application layers.

Why AI pentesting changes the attack surface model

Traditional pentests are usually narrow in scope, time-boxed, and manually driven, which means they under-sample complex environments. AI systems can expand the scope of what gets tested by exploring more paths, more combinations, and more target types in one cycle. That matters because modern compromise often depends on chained weaknesses rather than a single obvious flaw. In identity-heavy environments, those chains often involve credentials, service accounts, token reuse, and privilege escalation. AI makes those chains easier to search for at scale, which exposes gaps in segmentation and privilege design.

Practical implication: re-score risk based on attack paths and identity dependencies, not only on standalone vulnerabilities.

Context, not prompting, becomes the limiting control

The discussion points to a core operational issue: AI can generate output quickly, but it still depends on contextual inputs to be useful and safe. In offensive security, that means the quality of targets, assumptions, environment data, and constraints determines whether AI produces noise or insight. The same is true on defense. Security teams that lack accurate asset, identity, and dependency context will struggle to turn AI findings into action. This is where governance meets technical execution: without context, automation amplifies confusion rather than clarity.

Practical implication: invest in asset, identity, and dependency context before scaling AI-driven offensive or defensive workflows.


Threat narrative

Attacker objective: The attacker objective is to identify and exploit reachable paths into the environment faster than defenders can validate and close them.

  1. Entry begins with AI-assisted reconnaissance that rapidly maps exposed assets, interfaces, and likely weak points across a large environment.
  2. Escalation follows when automated reasoning identifies chained weaknesses, such as exposed services, weak access boundaries, or overly permissive identities.
  3. Impact occurs when validated attack paths are turned into repeatable exploit sequences that outpace quarterly remediation cycles and expose the full attack surface.

NHI Mgmt Group analysis

AI-driven offensive security is turning validation into a continuous control problem. Quarterly pentests were built for a slower threat environment, where humans could inspect a manageable subset of paths. AI changes the economics of discovery by making repeated, adaptive attack-path testing cheap and persistent. That means security assurance must move closer to continuous control verification, not periodic audit theatre. Practitioners should treat exposure management as an always-on discipline.

Context-rich testing is now the differentiator between useful automation and noisy automation. The article’s emphasis on context shows that AI is only as useful as the identity, asset, and dependency data surrounding it. That is directly relevant to NHI governance, where service accounts, tokens, and machine credentials often sit outside human review loops. The governance problem is not just speed, but whether the environment can describe itself accurately enough for AI to reason over it. Practitioners should prioritise control planes that expose accurate context to both human and machine testing.

Machine-speed offensive tooling exposes the gap between vulnerability discovery and remediation capacity. If remediation cycles remain measured in days or weeks, automation will keep finding issues faster than teams can close them. That turns backlog size into a control metric, not an operations metric. For identity-heavy environments, the most dangerous backlog items are credentials, access paths, and privilege assignments that remain valid long after they should have been removed. Practitioners should measure how quickly discovered exposure becomes closed exposure.

The offensive-security market is moving from point-in-time testing to self-modifying security workflows. The article signals a broader shift in how attack simulation, red teaming, and attack-surface management will be expected to operate. That does not eliminate human testers, but it changes their role toward higher-order reasoning, scenario design, and contextual judgement. For security programmes, the practical conclusion is clear: tools must be selected and governed for continuous use, not just occasional assurance.

What this signals

AI-driven offensive testing will pressure identity programmes to prove not just that controls exist, but that they fail safely under rapid, repeated validation. The operational question is no longer whether a weakness exists, but how quickly it can be discovered, triaged, and removed before automated exploitation compounds it.

Detection-response latency: when discovery becomes continuous, the security gap shifts from visibility to closure speed. That makes identity inventory quality, privilege review cadence, and remediation workflow integration the practical metrics that matter, especially where machine identities and human access intersect.


For practitioners

  • Build continuous attack-path validation Move from annual or quarterly pentests to continuous validation that re-tests exposure when identity, cloud, or application state changes. Focus on attack paths, not isolated findings, so new privilege paths and exposed services are re-evaluated in near real time.
  • Prioritise identity-rich attack surfaces Use AI-driven testing to target service accounts, API tokens, secrets, and privileged access paths first, because those paths frequently unlock broader movement across environments. Integrate findings with PAM and NHI inventories so exposed access can be closed in the same workflow.

Key takeaways

  • AI is turning offensive security into a continuous validation problem, which makes periodic testing structurally insufficient.
  • The most important control issue is no longer only whether weaknesses exist, but how quickly identity-rich attack paths can be found and closed.
  • Security teams that lack accurate asset and identity context will struggle to turn AI-driven testing into actionable risk reduction.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous validation aligns with monitoring for detectable events and exposures.
NIST SP 800-53 Rev 5SI-4AI-driven offensive testing supports ongoing system monitoring for weaknesses and abuse paths.
MITRE ATT&CKTA0007 , Discovery; TA0006 , Credential Access; TA0008 , Lateral MovementThe article focuses on AI-assisted discovery, credential abuse, and chained attack paths.
NIST AI RMFMANAGEThe article centres on operationalising AI safely inside security workflows.

Map AI testing to ATT&CK tactics so findings track real adversary behaviour, not isolated vulnerabilities.


Key terms

  • Attack-path validation: Attack-path validation is the practice of proving whether an attacker can move from one weakness to another until they reach meaningful impact. It goes beyond scanning by testing how exposures connect across identity, network, cloud, and application layers under realistic adversarial conditions.
  • Machine-speed defense: A defensive approach in which detection, analysis, containment, and access control operate fast enough to interrupt automated attacks while they are still unfolding. It depends on telemetry, automation, and clear ownership across identity and security workflows.
  • Detection-Response Latency: The elapsed time between identifying a security issue and executing a bounded, auditable fix. In data security programmes, long latency means exposure persists after discovery, which undermines the value of detection and weakens compliance evidence.
  • Context-Rich Testing: Security testing that links a vulnerability to the specific application, data set, identity, and business service it affects. This is more useful than raw findings alone because it shows whether an issue can actually expose sensitive health data or create a compliance failure.

What's in the full article

FireCompass's full blog covers the operational detail this post intentionally leaves for the source:

  • Benchmark comparisons showing how the AI agents performed against human testers across successive days
  • Direct commentary from Bruce Schneier and Bikash Barai on the shift from manual to continuous offensive security
  • The specific claim that AI can operate across a much larger attack surface in minutes rather than days or weeks
  • The full discussion of how context changes the usefulness of AI in pentesting and red teaming

👉 The full FireCompass post covers the fireside chat, performance comparisons, and the shift to continuous attack simulation

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It is designed for practitioners who need to connect identity controls to broader security operations.
NHIMG Editorial Note
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org