AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of all registered accounts. The findings provide an early indication of how AI is being incorporated into practical cybersecurity work alongside human expertise.
Across the competition, 17 of the top 25 teams had an AI agent. Collectively, agents were responsible for 4.2% of submitted flags and 4.6% of points awarded.
HTB cautioned that the figures do not demonstrate that the use of AI caused teams to perform better. However, the disproportionate presence of agents among the strongest teams suggests AI is moving beyond experimentation and becoming part of the toolkit used by experienced cybersecurity practitioners.
Cyber teams are solving challenges faster
The benchmark also points to a significant improvement in overall cybersecurity performance during the past three years. Median recorded time-to-solve fell from 26.1 hours in 2024 to 13.8 hours in 2026, a reduction of more than 12 hours.
Teams were also significantly more likely to complete the entire challenge board. Just two teams achieved this in 2024, rising to three in 2025 and 15 teams in 2026, despite the challenge board expanding during that period.
The results come as organisations explore how AI can augment security teams while simultaneously introducing new attack surfaces and risks. As AI agents gain greater autonomy and access to systems, applications and data, security teams will need to understand how to direct their activity and validate the decisions and outputs they produce.
The findings also raise questions about how cybersecurity skills will need to change. Rather than removing the need for technical expertise, greater AI adoption could place more emphasis on practitioners being able to assess AI-generated results, recognise errors and determine when human intervention is required.
Human judgement remains critical
Haris Pylarinos, Founder and CEO of Hack The Box, said AI’s growing role means organisations need to focus on the skills required to use the technology safely.
“The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation,” he said.
“What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less.”
HTB said the latest findings build on its previous research examining how practitioners perform when working with AI. While earlier testing looked at AI use in controlled conditions, the latest benchmark provides a view of where agents are being adopted when competitors are able to choose their own approach.
The results suggest the next phase of AI adoption in cybersecurity may therefore be as much a skills challenge as a technology one, with organisations needing practitioners capable of questioning, testing and validating what autonomous systems produce.

