
In Synack’s latest research, The State of Continuous Security Validation, the top-line finding matches what I hear from customers: people are confident in their pentesting programs, right up until a major finding contradicts them. We surveyed enterprise security leaders and found that 60% are very confident their testing cadence keeps pace with how fast their environment changes. Yet 95% still discover high or critical vulnerabilities outside their scheduled testing windows at least a few times a year, and 42% find them monthly.
Only 15% describe their pentesting programs as continuous today. Timing is a big reason why. A traditional pentest takes one to four weeks to deliver findings, which means 38% of organizations carry a quarter or more of their attack surface untested at any given moment. In general, most teams believe they’re covered because something is almost always being tested. But the report shows that coverage and confidence have drifted apart.
The Trust Problem Behind the Coverage Problem
The obvious answer to a coverage gap is more testing, more often. AI pentesting exists specifically to make that possible. Agentic tools can run reconnaissance and exploit validation continuously, at a scale no human team can match.
But many of those teams have found that AI can’t carry the program on its own. The report tells you why. Overall, 79% of security leaders would not act on an AI-generated finding until a human has confirmed it’s real and exploitable. Further, 67% treat an AI finding as a useful signal that still needs to be validated first, not a result they’d hand to a remediation team. In other words, the industry has the coverage problem partially solved and a trust problem sitting right behind it.
Humans in the Loop Cut Through the AI Noise
That skepticism is earned. I’ve spent the last several years building Sara, Synack’s AI pentesting agent, and the failure mode people worry about is real. Without a human in the loop and rigorous guardrails, agents produce plausible-looking findings that don’t hold up under scrutiny, or worse, take an action they shouldn’t have. The report backs this up: lack of trust in automated findings and too many false positives both rank among the most common barriers to continuous validation.
Put a human in that loop and things change. A finding reviewed by someone who understands the application, not just the agent’s output, stops being a probability and becomes a fact your team can act on. It’s also the only way remediation teams stop burning cycles on false positives, which is its own drain on a resource-constrained team.
AI and Humans, Not AI or Humans
This is where I think the future of pentesting is headed. Humans aren’t replacing AI, and AI isn’t replacing humans. We’ll see a division of labor that plays to what each side is actually good at. Agents win on volume. They can cover more surface area, faster, than any human team, and they’re relentless about it. Humans win on severity and criticality, because they understand how an application is used, the business logic around it, and how a chain of small issues becomes one serious one. I’ve seen this play out directly in our own benchmarking: agents surface a wide breadth of findings, mostly at the low-to-medium severity range, while the unique, creative, high-impact vulnerabilities are still overwhelmingly found by people. Security leaders in the report already operate this way. They’re using AI to lead reconnaissance, and humans lead the judgment calls, validating business risk and communicating it to stakeholders. Neither side does the other’s job better right now, and I don’t think that changes soon.
In fact the market has already made its choice. The report shows that continuous pentesting and validation is now the single most common method security leaders use to confirm whether a finding is exploitable, ahead of scanning and traditional pentesting. Getting there is less about accelerating AI adoption and more about building the validation habits that make its output trustworthy. It starts with making human-in-the-loop review the default across nearly every AI security workflow, and built into the process from the start. From there, I expect the trust gap outlined in this report to close over time as every validated finding, confirmed or rejected, feeds back into the agent, making it sharper at telling the difference on its own next time.
The 79% in this report isn’t a verdict against AI pentesting. It’s an accurate snapshot of where trust stands today. The programs that get this right will be the ones that stop treating human validation as a step and start treating it as the system.
Join our LinkedIn group Information Security Community!











