Cobalt Launches AI-Powered Autonomous Pentest for Continuous Application Security
Cobalt introduces an AI-assisted offering designed to deliver continuous offensive security testing and actionable penetration testing results within 24 hours.

Cobalt has unveiled Cobalt Autonomous Pentest, a new service aimed at providing continuous offensive security across an organization's application portfolio. This AI-assisted offering promises to deliver actionable penetration testing results in as little as 24 hours, addressing the growing challenge of keeping pace with rapidly evolving attack surfaces and AI-powered threats.
The surge in AI-assisted software development has accelerated release cycles, while attackers are simultaneously leveraging AI to automate reconnaissance and speed up exploitation. Traditional penetration testing, often conducted quarterly or monthly, is becoming insufficient to counter these advancements. As security teams grapple with expanding attack surfaces and constrained budgets, a more scalable approach to identifying and validating exploitable risk is urgently needed.
Integrated into the Cobalt Offensive Security Platform, Cobalt Autonomous Pentest achieves this scale through three core capabilities. Firstly, it ensures expert direction, with seasoned Cobalt pentesters guiding every engagement, reviewing execution plans, enforcing scope discipline, and applying creative adversary reasoning that pure AI tools cannot replicate. Secondly, its model-agnostic AI engine handles chain prediction, prioritization, and adaptive sequencing, informed by 13 years of exploit data and designed to adapt to evolving threat actor techniques.
Thirdly, the service delivers findings within 24 hours, integrating directly into tools such as Jira, GitHub, Slack, and over 50 others. Each finding includes proof of exploit where applicable, detailed reproduction steps, and tailored remediation guidance, enabling security teams to act swiftly. This approach acknowledges that while AI can automate many tasks, human expertise remains critical for effective offensive security.
According to Omdia Research, 94% of organizations recognize the importance of keeping humans in the loop for their offensive security programs. Cobalt's strategy places human expertise at the forefront of its autonomous solution, leveraging its community of approximately 500 rigorously vetted pentesters. "Meeting the demands of today’s development cycles requires more than automating traditional pentesting," stated Sonali Shah, CEO of Cobalt. "It requires rethinking how offensive security is delivered."
Shah further elaborated, "Only Cobalt unifies the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry’s largest dataset of real-world pentest results. Together, these capabilities enable security teams to continuously identify, prioritize, and remediate exploitable risk at the speed of modern software development."
The Cobalt Autonomous Pentest draws upon a vast dataset of over 10,000 critical and high-severity findings. This combination of extensive exploit data and human expertise allows organizations to achieve fast, flexible, and precise coverage across their entire attack surface. The service is designed to extend portfolio coverage and complement human-led, comprehensive penetration tests for compliance-driven engagements, offering the appropriate testing model and depth for each asset.