AI Security Tools Miss Critical Vulnerabilities as Hybrid Models Gain Favor
Event summary
- 78% of security teams report critical false negatives from automated scanning tools, per Cobalt's AI and Pentesting Pulse Report 2026.
- Adoption of hybrid human-AI testing models surged 22 points to 47%, while full automation dropped from 29% to 9%.
- AI/LLM vulnerabilities have a resolution rate of just 38%, with shadow AI and data poisoning among top attack vectors.
- Mean time to resolve (MTTR) for AI security issues rose to 36 days, up from 19 in 2025.
The big picture
The findings highlight growing pains in AI security as organizations struggle with the complexity of securing AI systems. The decline in trust for fully automated tools reflects broader industry challenges in detecting context-dependent vulnerabilities, particularly as AI applications proliferate across critical infrastructure. The surge in hybrid models suggests a recognition that human expertise remains essential for identifying and remediating sophisticated threats.
What we're watching
- Hybrid Model Adoption
- Whether security teams can sustain the shift to hybrid models while balancing cost and effectiveness.
- Vulnerability Resolution
- The pace at which AI/LLM vulnerability resolution rates improve given current 38% fix rate.
- Regulatory Scrutiny
- How increasing AI security incidents may trigger new compliance requirements for high-risk sectors.
