AI/LLM applications are becoming one of the riskiest assets

Analytics2026-07-09, 08:52
Researchers from Cobalt analyzed the results of five years of pentesting and two security professional surveys to assess the current state of application security in systems using AI technologies. The key takeaway from the Cobalt AI and Pentesting Pulse Report 2026: AI adoption is outpacing the development of its protection practices.
32% of findings in AI/LLM application assesments fall into the high-risk category. By comparison, across all other tested asset types this figure is around 12%. Researchers note that integrating AI tools into applications introduces new, AI-specific risks layered on top of traditional vulnerabilities.
Fixing vulnerabilities related to AI tools remains a serious challenge. The remediation rate has grown from 21.1% to 38.4%, but AI/LLM systems still show the lowest patch rate of all tested categories (for example, web apps show 73.7%).
At the same time, researchers observed a decline in trust toward automated pentests. While in 2025, 29% of organizations were ready to rely fully on automated tools, by 2026 only 9% remained. The reason is negative experience: 78% of companies encountered cases where automated scanners missed critical vulnerabilities.
More detailed survey results reflecting business responses are available in the full report.
The report stresses that as the remediation window for traditional vulnerabilities continues to shrink, the emergence of a new class of AI-specific flaws adds extra strain to security processes. Dependence on external AI providers and the lack of specialized expertise to fix AI-related issues make protecting such systems significantly harder. Therefore, when integrating AI tools into existing applications, organizations must strike a balance between leveraging new capabilities and maintaining effective risk management.
Vendors
Cobalt
Products
Cobalt Ai And Pentesting Pulse Report 2026