TL;DR: As software ships faster and AI-assisted development widens the window between exposure and verification, annual pentests no longer align with release velocity, according to Novee's webinar with UiPath and IDC. Continuous, validated offensive testing is becoming the practical response because security teams need machine-speed confirmation, not point-in-time assurance.
NHIMG editorial — based on content published by Novee: Stay Ahead of Cyber AI Attacks with Continuous AI Pentesting
By the numbers:
- 51% of security professionals still want agents limited to human-in-the-loop decisions, and only about 2% support full autonomy today.
Questions worth separating out
Q: How should security teams validate applications when release cadence is continuous?
A: Use continuous offensive testing that rechecks the application after each material change, not just at scheduled review points.
Q: Why do annual pentests fail to catch modern application risk?
A: Annual pentests assume the attack surface stays stable long enough for a point-in-time review to remain valid.
Q: What do security teams get wrong about scanner-driven testing?
A: They treat scanner output as proof of security rather than as partial evidence.
Practitioner guidance
- Tie pentest cadence to release velocity Match continuous offensive testing to how often applications, workflows, and AI-assisted code paths change.
- Prioritise identity-adjacent attack paths Focus validation on authorization boundaries, tenant isolation, service account behaviour, and delegated access patterns.
- Measure confirmation time, not scan volume Track how long it takes to prove a finding is real and route it to the right owner.
What's in the full article
Novee's full webinar covers the operational detail this post intentionally leaves for the source:
- The live discussion on how continuous pentesting replaces annual cycles in fast-moving development environments.
- Practitioner perspective on validating business logic flaws, tenant isolation, and chained attack paths that scanners miss.
- Market context on how AI-assisted coding changes the economics of validation, remediation, and testing coverage.
- The recorded conversation with UiPath CISO Scott Roberts, IDC senior analyst Katie Norton, and Novee co-founder and CEO Ido Geffen.
👉 Read Novee's webinar on continuous AI pentesting and the end of annual tests →
Continuous AI pentesting and the governance gap teams are missing?
Explore further
Continuous validation is becoming the governance model, not just the testing model. Annual pentesting assumes the environment is relatively stable between review windows. That assumption no longer holds when development pipelines, AI-assisted coding, and release frequency all accelerate at the same time. For identity-rich systems, the risk is not only code defects but also the identity and access paths those defects create. Practitioners should treat continuous validation as a control-plane issue, not a security afterthought.
A question worth separating out:
Q: How do organisations know whether continuous pentesting is actually reducing risk?
A: Look for fewer stale findings, faster remediation of validated issues, and better alignment between test coverage and current release activity. The signal is not volume, but the proportion of findings that are exploitable and acted on quickly. That shows the control is tracking real exposure instead of generating noise.
👉 Read our full editorial: Continuous AI pentesting is replacing annual testing models