Cybersecurity teams competing at the highest levels are decisively embracing artificial intelligence as a standard operational tool, according to fresh research from Hack The Box released this week. The platform's 2026 Global Cyber Skills Benchmark Research Brief, which tracks performance across a three-year period, reveals that leading teams are solving security challenges substantially faster than their peers, completing more of the required tasks, and systematically incorporating AI agents into their everyday workflows. This shift underscores a broader transformation underway across the cybersecurity profession, where the line between human and machine capability is becoming increasingly blurred—not through replacement, but through strategic collaboration.

The data presents a striking disparity between overall AI adoption and elite-level adoption. While AI agent accounts represent merely 2.7 per cent of all registered competitors on the platform, 17 of the top 25 performing teams—equivalent to 68 per cent—have integrated at least one AI agent into their toolkit. This concentration at the top tier suggests that advanced practitioners are leading the charge in experimental AI deployment, treating these tools as force multipliers rather than complete replacements for traditional skills. The agents themselves contributed modestly to overall competition output, accounting for 4.2 per cent of all submitted flags and 4.6 per cent of total points awarded, indicating that while their presence is significant strategically, human practitioners remain the primary drivers of solutions and success.

Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, cautioned against misinterpreting the findings as evidence that artificial intelligence alone elevates team performance. Instead, he emphasised that the data reveals a more nuanced reality: AI is increasingly appearing alongside, rather than instead of, the strongest technical practitioners. "As agents become more capable, human judgement, validation and hands-on technical skill become more important, not less," Pylarinos stated. This framing aligns with emerging industry consensus that the future of cybersecurity expertise lies not in artificial intelligence supplanting human professionals, but in the development of practitioners who can effectively direct, interrogate, and validate machine-generated recommendations.

The acceleration in problem-solving speed across the competition has been dramatic. The median time required to solve challenges decreased by more than 12 hours across just two years, dropping from 26.1 hours in 2024 to 13.8 hours in 2026. This improvement likely reflects a combination of factors: rising baseline skill levels among the competitor pool, better tools and methodologies, improved challenge design, and the introduction of AI-assisted workflows. More tellingly, the number of teams capable of completing the entire challenge board—representing comprehensive mastery—rose from a mere two teams in 2024 to three in 2025, then jumped substantially to 15 teams in 2026. This exponential growth suggests that AI-augmented methods are genuinely enabling deeper technical achievement among elite performers, not merely providing superficial shortcuts.

The cybersecurity landscape has simultaneously become more dangerous and more defended through AI integration. Hugging Face's disclosure of a significant security incident in July 2026 and OWASP's Q1 2026 GenAI Exploitation Roundup both underscore how artificial intelligence is being weaponised by adversaries while simultaneously strengthening defensive capabilities. This dual-edged dynamic creates an escalating arms race where the ability to understand, deploy, and counter AI-driven attacks has become a core competency. Security leaders worldwide are confronted with a fundamental challenge: artificial intelligence is no longer an optional enhancement to cybersecurity operations, but an essential component of both attack and defence infrastructure.

For organisational leaders responsible for security teams, the implications are substantial and immediate. The pathway forward is not simply acquiring AI tools and deploying them wholesale, but ensuring that practitioners possess the judgement, validation skills, and hands-on technical capabilities to direct machine learning systems effectively. This distinction is critical. A team equipped with sophisticated AI systems but lacking the expertise to evaluate their outputs would likely prove less effective than one with strong fundamental skills but no automation. The Hack The Box findings validate what many security professionals have intuited: AI works best when piloted by experienced practitioners who understand cybersecurity fundamentals deeply enough to challenge, redirect, and verify algorithmic recommendations.

The research builds upon earlier Hack The Box investigations into how artificial intelligence impacts security performance. Those previous studies employed controlled environments where practitioners worked explicitly with AI assistance, providing a laboratory view of human-AI collaboration. The new 2026 benchmark data, by contrast, captures what happens in a competitive environment where teams freely choose their own approaches, without external mandates to use or avoid AI. This methodological distinction is significant: it reveals genuine practitioner preference and actual workflow evolution rather than experimentally imposed conditions. The conclusion that emerges from this organic adoption pattern is that experienced cybersecurity professionals are voluntarily integrating AI into their operations because they recognise tangible performance benefits—not because of hype or vendor pressure.

The trajectory evident across these three years of data points toward a professionalisation of AI deployment in cybersecurity. What began as novelty and experimentation is maturing into standard practice among those practitioners who have demonstrated mastery through competition results. This mirrors earlier waves of technology adoption in the field: firewalls, intrusion detection systems, and threat intelligence platforms all faced initial skepticism before becoming indispensable infrastructure. Artificial intelligence agents appear to be following a similar path, moving from laboratory curiosity to practical necessity within security operations.

For Malaysian and Southeast Asian organisations, this research carries particular relevance. The region's rapidly expanding digital economy has created a voracious demand for cybersecurity talent, yet the supply of skilled professionals remains constrained. The ability of AI agents to amplify the productivity of experienced practitioners—as Hack The Box's data suggests—may help organisations stretch limited security resources further. However, the research simultaneously emphasises that such amplification depends entirely on having skilled humans to guide the machines. This underscores the continued importance of investing in cybersecurity education, training programmes, and the retention of experienced talent, even as automation capabilities expand. The solution, the evidence suggests, is not choosing between human expertise and AI capability, but orchestrating both strategically.