Threat Intelligence

Businesses Turn to AI-Powered Offensive Security as Threats Escalate

Dark Reading · 29 Aug 2026
Key Takeaway Before adopting AI-powered security testing tools, SMBs should ensure they understand the associated risks and have qualified staff or partners to oversee their safe and effective use.

As cyber threats grow more sophisticated, particularly those powered by artificial intelligence, organisations are ramping up investment in offensive security practices such as penetration testing and red teaming. According to Omdia analyst Theresa Lanowitz, speaking with Dark Reading, agentic AI—systems capable of autonomously performing tasks—is emerging as a tool that security teams can use to proactively test their own defences before attackers do.

While this approach offers real potential to strengthen security postures by identifying weaknesses faster and more thoroughly than manual testing alone, it also carries risks. Agentic AI tools used for offensive testing could themselves be misused, misconfigured, or targeted by adversaries, potentially creating new vulnerabilities rather than closing existing ones. The discussion highlights a broader trend: as attackers adopt AI to scale and refine their techniques, defenders are being pushed to adopt similar technologies simply to keep pace.

For small and medium businesses, this shift signals that offensive security testing—once seen as an enterprise-only investment—is becoming more accessible and relevant. However, adopting AI-driven tools requires careful vetting, as the same automation that improves testing efficiency could introduce new risks if not properly managed and overseen by skilled personnel.

AI security penetration testing red teaming offensive security emerging threats
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.