Digital locks showing AI and security vulnerabilities

Why It’s Vital to Stay Secure Whilst AI Accelerates Innovation

Threat actors use the same AI that defenders do

Innovation cycles are accelerating as enterprises embrace GenAI, cloud-native platforms and hyper-automation. But the same technologies driving innovation are giving attackers faster and more creative ways to compromise organizations. Anthropic recently revealed that threat actors have been experimenting with AI models to automate elements of cyberattacks against dozens of organizations. While some researchers have debated the extent of those claims, one thing is certain: attackers now have access to the same AI-powered tools that defenders use to discover weaknesses, and they can use them just as quickly. Fully autonomous cyberattacks are now an inevitable evolution. The attacks being debated today are likely to become commonplace in the near future, meaning security leaders must prove they can keep pace with business innovation without creating blind spots that adversaries will inevitably exploit.

AI innovation is outpacing AI security

Security leaders are increasingly aware that AI is creating as much risk as opportunity. Cobalt’s 2026 State of Pentesting Report found that 97% of organizations are actively adding AI capabilities to their software and services, yet confidence in securing those systems is moving in the opposite direction. Just 51% now believe they are equipped to address the security implications of AI, down sharply from 64% last year.

That lack of confidence is justified. One in five organizations report experiencing an LLM-related security incident over the past year, while 32% of AI and LLM vulnerabilities identified during pentests were rated high risk, which is 2.7 times the rate seen across applications overall.

AI vulnerabilities are still the hardest to fix

Finding vulnerabilities is only half the battle. The latest data shows AI applications remain the hardest systems to secure after issues are discovered. Only 38% of AI and LLM vulnerabilities have been remediated, the lowest resolution rate of any application category.

As organizations embed AI into customer-facing products and internal workflows, many security teams feel they’re losing ground. In fact, 61% of security professionals now say they would welcome a strategic pause in AI adoption to strengthen defenses before deployment continues. But business realities mean that pause is unlikely to happen. AI investment isn’t slowing down, so organizations need security strategies capable of keeping pace with innovation rather than trying to slow it down.

Balancing business agility with security

Organizations need to strike a balance between speed and security. Early adopters may gain a competitive advantage from deploying AI quickly, but not if they expose themselves to preventable risk. Cobalt’s analysis of thousands of penetration tests found that AI and LLM applications generate high-risk vulnerabilities at nearly three times the rate of conventional software.

Many of these weaknesses aren’t novel AI problems at all. Classic vulnerabilities such as SQL injection continue to appear alongside AI-specific flaws, suggesting organizations are rushing AI features into production before foundational security practices are firmly in place.

Know what you don’t know

Organizations also need to recognize the limits of their own expertise. LLM security remains a rapidly evolving discipline, and many teams simply don’t have the experience to identify or remediate these complex, context-dependent vulnerabilities.

Traditional automated scanners still have an important role, but they weren’t designed to identify sophisticated prompt injection attacks, insecure output handling or business logic abuse. Recent Cobalt research found that 78% of security teams have experienced critical false negatives from automated scanning tools, highlighting why automation alone cannot secure modern AI applications. These issues demand human creativity, adversarial thinking and experienced penetration testers who understand how AI systems behave in real-world environments.

Get ahead of the threat

Finally, true resilience requires continuous, human-led penetration testing to uncover the complex attack paths that automated tools routinely miss. AI should absolutely be part of modern offensive security, but it is most effective when combined with experienced security researchers who can distinguish genuine business risk from automated noise.

The reality is that attackers will continue targeting the lowest-hanging fruit. Organizations need to be more difficult to compromise than everyone else. By continuously identifying and fixing exploitable weaknesses before attackers find them, security teams can safely embrace AI innovation without sacrificing resilience.