Security practitioners now sit between two conversations that rarely meet: using AI to discover vulnerabilities faster while also securing the AI systems their organizations deploy. But new research from Pentest-Tools.com suggests the challenge is keeping up with the volume of vulnerabilities that AI tools generate.
In a survey of security practitioners using AI during pentesting engagements, only 20.3% of respondents said they have a workflow in place to triage 500 or more AI-generated vulnerability candidates from a single engagement. Another 38.6% said handling that volume would strain their team, while 29.7% said it would be unmanageable.
The findings suggest that AI is accelerating vulnerability discovery faster than organizations can reproduce, validate, prioritize, and remediate the results. For many users, the analysis, verification, and prioritization of findings have become bottlenecks.
Among the 147 practitioners who had used AI for finding generation, 87.8% encountered findings that required significant manual validation.
Practitioners described AI tools generating hundreds of findings, many of which proved to be fabricated exploits, duplicate findings, non-exploitable vulnerabilities, and even AI-generated CVEs that did not exist, leaving teams to spend days manually validating the results.
Beyond validation, those surveyed consistently identified business logic as the area where AI struggles most. Instead of missing technical vulnerabilities, they described how AI does not understand how applications are supposed to behave.
Respondents consistently named business logic understanding above exploit chaining and creativity as AI’s biggest limitation.
For instance, respondents said AI pentesting tools can identify SQL injections, but they struggle to understand business rules, such as a discount coupon that should only work once per customer. They also described logic flaws: adding a negative quantity to a cart resulted in free purchases, and changing a user ID in a URL exposed another user’s data.
Respondents said hallucinated exploits and fabricated vulnerabilities eroded confidence in subsequent findings, forcing practitioners to verify even legitimate results more carefully.
“[What has been your biggest frustration with AI pentesting tools you have evaluated or purchased?] Confidence that turns out to be just a big lie.” Security Manager/CISO at a mid-market company
AI system testing is also becoming part of everyday security work. More than 9 in 10 practitioners (92.4%) either already test AI-enabled systems and LLM-integrated applications or plan to within the next 12 months. Three-quarters (75.3%) are doing it today; the rest expect to start within the year.
Stakeholder expectations are also increasing. More than one-third (37.3%) of practitioners said internal stakeholders now expect more frequent penetration testing than they did 12 months ago because of growing awareness of AI-assisted attacks.
Pentest-Tools.com spokesperson quote for approval:
Adrian Furtuna, CEO and founder of Pentest-Tools,com, said, “There have been significant advances in how AI is accelerating vulnerability discovery. The challenge now is making sure those findings are accurate enough to limit manual work, instead of creating more of it.”
Conducted in June 2026, the survey gathered responses from 158 security practitioners who use AI-assisted vulnerability assessment and validation tools in their day-to-day work, including penetration testers, security engineers, AppSec professionals, DevSecOps practitioners, consultants, and MSSPs. Unlike many AI security surveys aimed at executives and technology buyers, this research examines how AI is changing the work of practitioners performing security testing.
The complete survey findings and dataset are available at: https://pentest-tools.com/insights/ai-pentesting-survey

