Hack The Box Report Finds AI Agents Used by 68% of Top 25 Cybersecurity Teams

Hack The Box Report Finds AI Agents Used by 68% of Top 25 Cybersecurity Teams
🕧 6 min

Three-year benchmark finds median solve times dropped by more than 12 hours, while full-board completions surged from two teams in 2024 to 15 in 2026

Hack The Box (HTB),(opens in new tab) the cyber readiness platform for humans and AI, released its 2026 Global Cyber Skills Benchmark Research Brief. The brief includes a three-year analysis revealing that cybersecurity teams are reaching successful solutions significantly faster, completing more of the challenge set, and increasingly incorporating AI agents into their work.

Also Read: IT Tech Pulse Exclusive Interview with Ken Claffey Chief Executive Officer and President of VDURA

“Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them,” said Haris Pylarinos, Founder and CEO of Hack The Box.

The strongest evidence of AI adoption emerged among the competition’s top performers. AI agent accounts made up just 2.7% of all registered accounts, yet 17 of the top 25 teams (68%) had one. Those agents accounted for 4.2% of submitted flags and 4.6% of points awarded. The findings do not establish that AI caused teams to perform better. They do, however, show that AI is already becoming part of the toolkit used by many of the competition’s strongest teams.

Performance across the competition has also shifted substantially over the past three years. Median recorded time-to-solve dropped from 26.1 hours in 2024 to 13.8 hours in 2026, a reduction of more than 12 hours. At the same time, the number of teams completing the entire challenge board rose from two in 2024 and three in 2025 to 15 in 2026, even as the board expanded.

The findings come as AI is changing both sides of the cybersecurity equation. Recent industry disclosures, including Hugging Face’s July 2026 incident disclosure and OWASP’s Q1 2026 GenAI exploit roundup, show how AI is creating new risks while also becoming part of both the attack surface and the defensive response. For security leaders, the challenge is not simply adopting AI, but making sure practitioners have the skills and judgment to direct, test and validate its work.

Also Read: IT Tech Pulse Exclusive Interview with Syed Ali Founder and Chief Executive Officer of EZO

“The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation,” said Haris Pylarinos(opens in new tab), Founder and CEO of Hack The Box. “What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less.”

AI is changing how top cyber teams work

The findings build on earlier HTB research examining AI and cybersecurity performance. While the earlier controlled benchmark explored what happens when practitioners work with AI, the latest data provides a view into where AI agents appear when competitors are free to choose their own approach.

Together, the findings suggest that AI is moving from experimentation to the working methods of experienced cybersecurity practitioners. At the same time, the results reinforce the importance of human expertise in directing, evaluating and validating AI-generated work.

Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.

  • Business Wire has been synonymous with well-known press release distribution for more than half a century. Owned by Berkshire Hathaway, it combines regulatory compliance expertise with a powerful media network, helping enterprises large and small share news that influences markets and decision-makers alike.

Recommended Reads :