‘I bought the tool to save time, but I did more manual work than before’: Pentesters are finding more bugs with AI than they can fix
Hallucinated exploits and fabricated vulnerabilities are adding to pentester workloads
AI-powered penetration testing tools are getting out of hand, according to new research, generating more findings than security teams can validate.
Nine-in-ten security practitioners surveyed by Pentest-Tools who have used AI to generate findings said the results needed significant manual validation.
Just over six-in-ten said this was the case with between 5% and 25% of findings, with 27% saying that more than a quarter of AI-generated findings needed validation.
Respondents reported fabricated exploits, duplicate findings, non-exploitable vulnerabilities, and even AI-generated CVEs that turned out not to exist, leaving teams to spend days manually validating the results.
"An AI tool spits out 300 findings. I spent two days triaging, and 250 were junk - duplicate vulns, potential SQLi that is not exploitable, or AI-made-up CVEs that do not exist," one respondent said. "I bought the tool to save time, but I did more manual work than before."
Only one-in-five respondents said they have a workflow in place allowing them to triage 500 or more AI-generated vulnerability candidates from a single engagement.
Another 39%, meanwhile, said handling that volume would strain their team, while 30% said it would be unmanageable.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Even legitimate results needed to be checked more carefully, respondents noted, because hallucinated exploits and fabricated vulnerabilities are eroding confidence in subsequent findings.
One security manager at a mid-market company said their biggest frustration with AI pen testing tools was "confidence that turns out to be just a big lie.”
Meanwhile, they consistently named business logic understanding above exploit chaining and creativity as AI's biggest limitation.
For instance, one respondent said that AI pen testing tools were fine when it came to identifying SQL injections, but struggled to understand business rules, such as a discount coupon that should only work once per customer.
They also described logic flaws: for example, adding a negative quantity to a cart resulted in free purchases, and changing a user ID in a URL exposed another user's data.
AI pen testing tools are growing in popularity
Despite notable concerns, more than nine-in-ten respondents said they were either already using AI-enabled systems or planning to do so within the next 12 months.
AI is proving a useful tool in vulnerability detection, with 74% of respondents using the technology in this domain. It’s also being used in other administrative-type tasks, such as report writing (69%), documentation and findings tracking (66.5%).
Notably, however, AI isn’t quite as popular where live judgement is required. Just over one-third (37%) use it for exploitation and attack path chaining, 35% for remediation validation and retesting, and a quarter for post-exploitation and lateral movement.
Expectations are also increasing, with 37.3% saying that internal stakeholders now expect more frequent penetration testing than they did 12 months ago because of growing awareness of AI-assisted attacks.
Almost half said they test AI systems only when a stakeholder specifically requests it.
“There have been significant advances in how AI is accelerating vulnerability discovery," said Adrian Furtuna, CEO and founder of Pentest-Tools. "The challenge now is making sure those findings are accurate enough to limit manual work, instead of creating more of it.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Rapid7 expands UK channel reach through Exclusive Networks partnershipNews Exclusive Networks will act as the vendor’s strategic distributor in the UK as it looks to strengthen partner enablement and expand customer access
-
Reports: UK could consider regulation amidst growing 'rogue AI' concernsNews New AI minister said regulation is on the table, but only if public safety is at risk from AI
-
Pentesters are now a CISOs best friend as critical vulnerabilities skyrocketNews Attack surfaces are expanding rapidly, but pentesters are here to save the day
-
Cyber professionals call for a 'strategic pause' on AI adoption as teams left scrambling to secure toolsNews Security professionals are scrambling to secure generative AI tools
-
Bugcrowd’s new MSP program looks to transform pen testing for small businessesNews Cybersecurity provider Bugcrowd has launched a new service aimed at helping MSP’s drive pen testing capabilities - with a particular focus on small businesses.
-
Building a new approach to security with the next generation of penetration testingSponsored Combining human-led testing with continuous automated scanning can elevate your security regime
-
OpenAI to pay up to $20k in rewards through new bug bounty programNews The move follows a period of unrest over data security concerns
-
Kali Linux releases first-ever defensive distro with score of new toolsNews Kali Purple marks the next step for the red-teaming platform on the project's tenth anniversary
-
Podcast transcript: Meet the cyborg hackerIT Pro Podcast Read the full transcript for this episode of the IT Pro Podcast
-
The IT Pro Podcast: Meet the cyborg hackerIT Pro Podcast Resistance is futile - offensive biotech implants are already here