TL;DR: AI is pushing pentesting, red teaming, and vulnerability discovery toward continuous, event-triggered, machine-speed execution, according to FireCompass, while Bruce Schneier and Bikash Barai argue that the real shift is from human cadence to self-modifying security workflows. The implication is that attack-surface validation, contextual reasoning, and remediation loops now need to be governed as a programme, not a quarterly exercise.
NHIMG editorial — based on content published by FireCompass: AI and the Future of Offensive Security: Insights from Bruce Schneier and Bikash Barai
By the numbers:
- A year ago, AI could perform only 60-70% of what an experienced human could.
Questions worth separating out
A: Security teams should move from periodic, point-in-time testing to continuous validation across the full environment.
Q: Why do annual pentests fail to catch modern application risk?
A: Annual pentests assume the attack surface stays stable long enough for a point-in-time review to remain valid.
Q: What should teams do when AI finds attack paths faster than remediation can keep up?
A: They should use exposure-driven prioritisation, with identity and privilege issues at the top of the queue.
Practitioner guidance
- Build continuous attack-path validation Move from annual or quarterly pentests to continuous validation that re-tests exposure when identity, cloud, or application state changes.
- Prioritise identity-rich attack surfaces Use AI-driven testing to target service accounts, API tokens, secrets, and privileged access paths first, because those paths frequently unlock broader movement across environments.
What's in the full article
FireCompass's full blog covers the operational detail this post intentionally leaves for the source:
- Benchmark comparisons showing how the AI agents performed against human testers across successive days
- Direct commentary from Bruce Schneier and Bikash Barai on the shift from manual to continuous offensive security
- The specific claim that AI can operate across a much larger attack surface in minutes rather than days or weeks
- The full discussion of how context changes the usefulness of AI in pentesting and red teaming
👉 Read FireCompass's analysis of AI-driven offensive security and continuous pentesting →
AI in pentesting and red teaming: what changes for defenders?
Explore further
AI-driven offensive security is turning validation into a continuous control problem. Quarterly pentests were built for a slower threat environment, where humans could inspect a manageable subset of paths. AI changes the economics of discovery by making repeated, adaptive attack-path testing cheap and persistent. That means security assurance must move closer to continuous control verification, not periodic audit theatre. Practitioners should treat exposure management as an always-on discipline.
A question worth separating out:
Q: How can organisations keep AI offensive testing accurate and useful?
A: They need high-quality context around assets, identities, and dependencies so AI does not just generate noise. Accurate inventories, access relationships, and ownership data let automation distinguish true risk from irrelevant findings. Without that context, AI scales uncertainty instead of assurance.
👉 Read our full editorial: AI-driven offensive security is changing the shape of pentesting