TL;DR: Only 32% of enterprise attack surfaces are tested on average, leaving a 68% blind spot that attackers can exploit at machine speed, according to Synack’s Omdia-backed survey. Agentic AI expands coverage and testing frequency, but human validation remains necessary for business logic flaws, IDOR, and safe use in high-assurance environments.
NHIMG editorial — based on content published by Synack: Why the Future of Pentesting Needs Humans and Agentic AI Working Together
Questions worth separating out
Q: Where does agentic AI pentesting fail in practice?
A: It fails most often where vulnerability discovery depends on business context, ownership, or multi-step intent rather than obvious technical defects.
Q: Why do AI testing tools need strict containment in critical environments?
A: Because an adaptive testing system can change tactics mid-run and accidentally move beyond the intended scope if controls are loose.
Q: What do organisations get wrong about AI-assisted pentesting?
A: They often assume the model itself is the product, when the real control surface is the surrounding orchestration, evidence handling, and permissions model.
Practitioner guidance
- Shift pentesting from snapshots to continuous coverage Use agentic AI to enumerate and re-test changing assets between human engagements, especially cloud-native apps, APIs, and ephemeral infrastructure.
- Treat the testing platform as a privileged NHI Apply least privilege, network segmentation, audit logging, and explicit revocation paths to the agentic testing system itself.
- Reserve human validation for logic-heavy findings Route business logic issues, IDOR candidates, access-control chains, and multi-step abuse paths to experienced testers before remediation tickets are created.
What's in the full article
Synack's full blog post covers the operational detail this post intentionally leaves for the source:
- The survey breakdown behind the 32% coverage figure and how the respondents were distributed across enterprise sizes.
- The practical AI-first, human-validated operating model Synack describes for blending automated discovery with researcher review.
- The safety controls the article says are needed for critical infrastructure, including network-level containment and emergency stop logic.
- The examples of AI-discovered vulnerabilities, including the Firefox testing case and the business logic scenarios humans still catch best.
👉 Read Synack's analysis of why pentesting needs humans and agentic AI together →
Agentic AI pentesting and the coverage gap , are controls keeping up?
Explore further
Machine-speed offense has turned pentesting coverage into a governance metric. When attackers can probe thousands of requests per second, annual or narrowly scoped testing becomes a record of what was once true, not a control over current exposure. The practical consequence is that security leaders must treat test coverage as an operational risk indicator, not a compliance checkbox, and tie it to the realities of cloud churn, APIs, and delegated access.
A question worth separating out:
Q: How should organisations govern AI pentesting platforms?
A: They should govern them like privileged non-human identities with clear ownership, least privilege, segmentation, and revocation. If the platform can probe production-resembling systems, its actions must be logged and bounded as carefully as any high-risk workload. Human approval should remain the final control before findings become operational decisions.
👉 Read our full editorial: Human and agentic AI pentesting must close the coverage gap