TL;DR: Only 21% validate security on every release even as 76% deploy significant changes weekly or faster, and 48% say findings are outdated on arrival, according to Aikido’s report based on 400 CISOs, CTOs and senior engineering leaders across Europe and the US. Traditional pentesting is being overtaken by release velocity, so continuous validation becomes the practical security question.
NHIMG editorial — based on content published by Aikido: 2026 State of AI in Pentesting
By the numbers:
- Only 21% validate security on every release, despite 76% deploying significant changes weekly or faster.
- 69% would validate security on every release or at least quarterly if cost and resources weren't a constraint.
Questions worth separating out
A: Security teams should link validation to release events, not to fixed calendar intervals.
Q: Why do scheduled pentests miss issues in AI-assisted development pipelines?
A: Because the environment can change multiple times between test windows.
Q: What do security teams get wrong about continuous validation?
A: They often treat it as a tooling upgrade instead of a governance model.
Practitioner guidance
- Map validation frequency to release risk Classify applications by deployment cadence, exposure level, and identity dependency, then set testing and review frequency to match the highest-risk change class rather than using one calendar for everything.
- Embed security gates into CI/CD change events Tie policy checks, dependency analysis, and targeted manual review to merge, build, and deploy stages so that high-risk changes cannot bypass verification simply because the scheduled pentest has not happened yet.
- Include service credentials in release assurance Review build tokens, deployment accounts, and API credentials as part of the validation scope, because many exploitation paths begin with over-permissioned automation rather than the application code itself.
What's in the full report
Aikido's full report covers the survey detail this post intentionally leaves for the source:
- Breakdowns of how 400 CISOs, CTOs, and senior engineering leaders answered questions about AI and pentesting.
- The underlying survey context behind the 21% every-release validation figure and the 48% stale-findings result.
- Perspective from contributors across OWASP, IDC, Frost & Sullivan, and the UK Cabinet Office on how testing models are changing.
- Additional detail on what teams want from the next generation of pentesting, beyond the headline metrics.
👉 Read Aikido's 2026 State of AI in Pentesting report →
AI pentesting gaps: are release cycles outrunning validation?
Explore further
AI creates a release-velocity security gap: the central governance problem is no longer whether organisations test, but whether the test cycle matches the pace of delivery. When 76% of teams ship significant changes weekly or faster, scheduled pentests increasingly describe yesterday's environment. That makes security validation a change-management issue, not just an assurance activity.
A question worth separating out:
Q: How do teams decide which applications need release-linked security testing?
A: Prioritise systems with frequent deployments, internet exposure, customer data, or heavy identity and automation dependencies. Those environments create the highest probability that a vulnerability will be introduced and exploited before the next scheduled test. Low-change systems can use lighter validation, but not no validation.
👉 Read our full editorial: AI is outpacing pentesting in fast-release software delivery