I came across this thread on Reddit where someone was asking what they should be doing to survive the next few years in pen testing, given everything happening with AI. The replies were a mix of genuine advice and total doom-scrolling.
It prompted me to write this because I keep hearing the same conversation. At conferences. On LinkedIn. In DMs. “Is AI going to replace us?”
Short answer: no. But it is going to kill off a certain type of pentester, and honestly, good riddance.
We’ve been here before
When automated vulnerability scanners first hit the market, the panic was identical. “Why would anyone hire a person when Nessus can find the bugs?” Some firms did exactly that — bought a scanner license, ran it against client infrastructure, copy-pasted the output into a Word doc, and called it a pen test.
Those firms still exist. They charge four grand for a Nessus scan with a logo on it. Their clients don’t know any better until something actually goes wrong.
AI is going to do to those firms what the scanners should have done years ago. If your entire value proposition is “I can run a tool and rearrange its output,” then yes, a language model can do your job. Probably already can.
But that was never real pen testing. That was theatre.
Faking competence just got easier
I’m seeing it already. People using AI to write reports that sound convincing, generate scripts that look reasonable, and produce deliverables that pass a surface-level review. If you’re a hiring manager who evaluates candidates by their written output alone, you have a problem.
The gap shows up on live engagements. When the initial foothold doesn’t work and you need to think laterally. When the client’s environment is weird and nothing from the playbook applies. When you need to chain three low-severity findings into something that actually demonstrates business risk.
AI can’t do that. It can’t sit in a network at 2am working out why the domain trust is configured the way it is and what that means for lateral movement. It doesn’t have the instinct that comes from hundreds of engagements where you’ve seen the same misconfigurations in different shapes.
I’ve interviewed people recently who clearly had AI-assisted CVs and portfolios. They looked great on paper. Fell apart in the technical interview. That gap is only going to widen.
The attack surface is getting worse, not better
Every company bolting AI into their stack right now is creating new attack surface. Most of them don’t fully understand what they’ve deployed. Prompt injection, training data poisoning, insecure API integrations to model endpoints, overly permissive service accounts for ML pipelines. We’re finding all of it on engagements.
We had a client recently who’d deployed an internal chatbot connected to their knowledge base. HR documents, finance reports, internal strategy docs, all accessible through the retrieval layer. No access controls. Basic prompt manipulation got us salary data and board meeting minutes. The chatbot was never in scope because nobody had thought of it as an attack surface. It was just “the AI thing the innovation team set up.”
That’s brand new work. The companies rushing to adopt AI are the same ones who’ll need someone to test it. And the testing methodology for AI systems is still being written. If you take the time to understand how these systems actually work, how embeddings are stored, how RAG pipelines retrieve data, where the trust boundaries are, you’re going to be busy for years.
Tradecraft is about the “why,” not the “how”
AI can find an SQL injection. Give it a target and the right tooling and it’ll probably identify the vulnerability faster than a human. Fine.
It can’t explain to a CTO why that specific injection matters for their business. It can’t walk a board through the chain: here’s the injection, here’s how we used it to access the database, here’s the customer data we extracted, here’s what that means for your GDPR obligations, here’s what a regulator would say. That conversation requires understanding the client, their industry, their risk appetite, and the political dynamics of who in the room is going to push back.
Every client I’ve worked with in 11 years has been different. The technology might be similar but the context never is. A SQL injection in a healthcare provider’s patient records system is a completely different conversation to the same vulnerability in an internal dev tool that three engineers use. AI doesn’t understand that difference. A good pentester does.
The report is where most of the value lives for the client. Not the finding itself, the translation. What does this mean, how bad is it really, what should we fix first, and what can we get away with accepting for now? That’s judgement and experience. Not getting automated any time soon.
Use the thing
I use AI tools. Our team uses them. They’re useful for generating payloads to test edge cases, writing quick scripts for data parsing mid-engagement, summarising large volumes of output when you need to pull patterns out of logs fast.
It’s another tool in the kit. Like Burp. Like Bloodhound. Like the custom scripts everyone accumulates over years of testing. You learn what it’s good at, you learn where it falls over, you use it when it makes sense.
The pentesters who refuse to touch AI tools are making the same mistake as the ones who refused to learn cloud testing five years ago. The technology moves and you move with it. Understand how attackers are using AI — phishing, social engineering, automated recon, polymorphic malware — and use that knowledge to test your clients against realistic threats.
The trust problem nobody talks about
The more experience you get, the less you trust automated tools on production environments. I’ve seen scanners take down critical systems. I’ve seen automated exploitation tools fire payloads at things they shouldn’t have touched. The last thing anyone needs on a red team assessment is an AI agent going rogue on a production database because it didn’t understand the context.
Clients trust us because we understand what not to touch. We know the difference between a test environment and the live trading platform. We check before we fire. That judgement, knowing when to stop, when to ask, when the risk of testing outweighs the value of the finding, is not something you can automate. You build it from years of nearly breaking things and learning where the lines are.
If you hand AI an objective and set it loose, it’ll optimise for that objective. It won’t think about the collateral damage. Pen testing has always required restraint as much as capability.
Where does that leave you?
If you’re worrying about your career in pen testing, ask yourself whether you can do the job without the tools. If Nessus disappeared tomorrow, could you still find the vulnerabilities? Could you still explain them to someone who doesn’t know what a subnet is?
If yes, you’re fine. The market needs more people like you, not fewer.
If no, then AI is the least of your problems. You were already on borrowed time. AI just makes it harder to hide.
The fundamentals haven’t changed. Learn how things actually work. Break them. Work out why they broke. Then explain it to someone who cares about the business risk more than the technical detail. That’s the job. It’s always been the job.
Props to everyone still putting in the hours to get their hands dirty and learn this stuff properly. If you’re feeling the pressure and want to talk about actually levelling up your testing beyond the hype, you know where I am.