ChannelLife US - Industry insider news for technology resellers
United States
Cobalt launches autonomous pentest for continuous testing

Cobalt launches autonomous pentest for continuous testing

Fri, 24th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Cobalt has launched Autonomous Pentest, a new service for continuous security testing across application portfolios.

The product combines artificial intelligence with oversight from human pentesters and can return findings within 24 hours.

The launch comes as software teams release code more quickly and security groups face pressure to test a wider range of applications with limited resources. Attackers are also using artificial intelligence to speed up reconnaissance and exploitation, making less frequent testing harder to justify.

Autonomous Pentest sits within Cobalt's Offensive Security Platform and is designed to test applications across a customer's software estate. Seasoned pentesters remain involved in every engagement, reviewing execution plans and enforcing scope, while an AI system handles task sequencing and prioritisation.

The model behind the service is informed by more than 13 years of exploit data and draws on more than 10,000 critical and high-severity findings from previous work.

Results are delivered into tools including Jira, GitHub and Slack, alongside more than 50 other integrations. Each finding includes proof of exploit where relevant, steps to reproduce the issue and remediation guidance for development or security teams.

Human role

A central part of the launch is Cobalt's effort to position human testers alongside automated workflows rather than in opposition to them. The company cited Omdia research showing that 94% of organisations see value in keeping humans involved in offensive security programmes.

The service uses Cobalt's network of about 500 vetted pentesters, known as Cobalt Core. The group is intended to provide judgement and adversarial reasoning in areas where automated systems may fall short.

"Meeting the demands of today's development cycles requires more than automating traditional pentesting," said Sonali Shah, Chief Executive Officer of Cobalt.

"It requires rethinking how offensive security is delivered. Only Cobalt unifies the four critical elements of modern offensive security: elite human expertise, a context-aware platform, AI-powered orchestration, and the industry's largest dataset of real-world pentest results. Together, these capabilities enable security teams to continuously identify, prioritize, and remediate exploitable risk at the speed of modern software development," Shah said.

Broader shift

The release reflects a wider shift in cybersecurity as suppliers look for ways to apply artificial intelligence to labour-intensive testing and monitoring work. In application security, that pressure has increased as development teams adopt AI-assisted coding tools that can increase the volume and pace of software releases.

Traditional penetration testing is often carried out quarterly or monthly, depending on budget and compliance needs. Cobalt is targeting the gap between those scheduled assessments and the pace at which modern applications change, arguing that larger portfolios need more regular testing.

The company also framed the service as complementary to conventional human-led assessments rather than a full replacement. It is intended to extend testing coverage across more assets, while comprehensive human-led pentests remain better suited to compliance-driven engagements and deeper reviews.

That distinction matters in a market where buyers are weighing speed and scale against confidence in the results. Automated tools can increase testing frequency, but security teams often still want evidence that findings are validated and relevant to real-world attack paths.

Cobalt said its service is model-agnostic, meaning it is not tied to one artificial intelligence model. This allows the system to adapt as threat techniques change and as underlying AI technology develops.

Cobalt has been known for pentesting as a service, and the new launch extends that approach in a more automated format. By embedding the service in its existing platform and linking findings to common developer and collaboration tools, the company is seeking to place offensive testing closer to day-to-day software delivery workflows.

Thousands of customers and hundreds of partners use Cobalt's services, according to the company. Its global network includes more than 500 vetted security specialists.

Cobalt said Autonomous Pentest will be generally available in August 2026.