For those who have trialed an AI pentest solution: what was the single biggest gap you encountered?
Sort by:
CISO in Softwarea day ago
Sometimes, they need more environmental context to target the right APIs and instances.
Sometimes, they need more environmental context to target the right APIs and instances.
Lack of mature vendor solutions41%
Trust in AI accuracy65%
Budget constraints29%
Skills to operate the tools47%
It is the first time I heard about Loop14%
I know Loop but I don't use it42%
I know and I use it but it is not a Company streamlined product46%
It is part of the toolkit in the Company and widely adopted30%
I know it but we selected another product (please specify in the comments).1%
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2025 Gartner, Inc. and/or its affiliates. All rights reserved.
From my experience, the biggest gap with AI-driven pentest tools is depth of context. They’re good at scanning broad attack surfaces quickly, but they often miss nuanced issues—like business logic flaws, privilege escalation paths, or chained exploits across systems. Without human creativity to connect the dots, results risk being shallow. The question is how to best blend AI speed with human expertise for meaningful coverage.