SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
AI agents used by 68% of top cyber teams, study finds

AI agents used by 68% of top cyber teams, study finds

Thu, 27th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Hack The Box has published research showing that AI agents were used by 68% of the top 25 cybersecurity teams in its latest benchmark. The study also found that teams solved challenges faster than in previous years.

The three-year analysis tracked changes in team performance from 2024 to 2026 and examined how AI agents appeared in competition workflows. AI agent accounts made up 2.7% of all registered accounts, yet 17 of the top 25 teams included one.

Those accounts contributed 4.2% of submitted flags and 4.6% of points awarded. The figures suggest AI tools are appearing more often among high-ranking teams, although the data does not show that AI itself caused stronger results.

Overall performance shifted sharply over the period covered by the benchmark. Median recorded time-to-solve fell from 26.1 hours in 2024 to 13.8 hours in 2026, cutting more than 12 hours from the midpoint result.

Board completion rates also increased. Two teams completed the entire challenge board in 2024, three did so in 2025, and 15 reached full-board completion in 2026, even though the board had grown in size.

Top team use

The concentration of AI agent use among leading teams stands out because the accounts remain a small minority overall. That pattern points to early adoption by more advanced competitors rather than broad use across the field.

The findings come as companies and security teams weigh how generative AI and autonomous software tools fit into day-to-day cyber operations. The debate has widened as AI systems are used both to support defenders and to create new routes for attackers.

Industry incidents have added urgency to that discussion. Hack The Box pointed to recent disclosures, including a July 2026 incident at Hugging Face and an OWASP roundup of generative AI exploits in the first quarter of 2026, as signs that AI is becoming part of both the attack surface and the defensive response.

For employers and team leaders, the benchmark raises questions about training as much as tooling. If AI agents are becoming more common in technical work, organisations may need staff who can direct outputs, test suggestions, and check whether machine-generated steps are safe and accurate.

That emphasis on human oversight is central to the report's framing of the results. The data indicates that AI is being used alongside experienced practitioners rather than replacing them, especially in settings where technical judgment affects outcomes.

"The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation," said Haris Pylarinos, Founder and CEO of Hack The Box.

Pylarinos also highlighted the role of practitioners in supervising the technology.

"What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less," he said.

Broader trend

The latest benchmark builds on earlier work by Hack The Box that explored how practitioners performed when using AI in a more controlled setting. In the new analysis, competitors were free to choose their own methods, giving a broader view of where AI agents actually appear in practice.

That distinction matters because controlled testing can isolate the effect of a tool, while open competition can reveal whether people choose to adopt it at all. In this case, the benchmark suggests AI agents are entering real workflows among teams already performing at a high level.

At the same time, the numbers underline how limited adoption still is in absolute terms. With AI agents accounting for 2.7% of registered accounts, the benchmark does not describe a market in which such tools are universal. Instead, it points to selective uptake in a field where skill, speed, and validation remain decisive.

The challenge for security organisations may be deciding whether that pattern represents an early signal of wider operational change. If teams using AI are already common among top performers, boards and senior security executives may face pressure to set policies on where such agents can be used and how their work should be reviewed.

Hack The Box operates a cyber training and assessment platform used by a large online community as well as commercial and public sector customers. The benchmark adds to a growing body of industry research on how AI is changing technical security work, but its clearest finding is simple: the strongest teams are getting faster, and many are already using AI agents as part of the job.