Extend SECTION SETTINGS - THIS ELEMENT WILL BE SHOWN ONLY IN THE CONTENT EDITOR
On-Demand · BrightTALK Enterprise AI Security and Governance Summit 2026

The New AI-Enabled Offense Against Machine-Speed Adversaries

Tim Nordvedt, Senior Manager of North America Solutions Architecture at Synack, breaks down how frontier AI models are compressing the window between vulnerability and exploit, and gives you a framework for telling real agentic pentesting capability apart from repackaged automation.

Recorded live at BrightTALK's Enterprise AI Security and Governance Summit, Track: AI Security Operations and Threat Intelligence.

Key Learning

The Access Curve Collapsed, Not the Threat

The vulnerabilities in your environment haven't changed. What changed is how many people, and now how many machines, can reach and exploit them, and how fast.

Key Learning

Proven Is the New Constraint

Mythos flagged 6,202 high/critical findings. Only 75, about 1.2%, were ever patched. Finding stopped being the hard part; proving what's real and worth a change window is.

Key Learning

The Harness Beats the Model

Orchestration, guardrails, and human validation determine whether AI pentesting results can be trusted, not which frontier model a vendor has access to.

Why This Matters

Discovery volume is rising, remediation windows are shrinking, and most of the attack surface still isn't tested at all.

48,185 CVEs were published in 2025, up over 20% year over year, before frontier models entered the picture. CISA's Binding Operational Directive 26-04 now requires fixes in as little as three days for the most severe, known-exploitable findings, a bar CISA expects the private sector to adopt within 12 to 18 months. Meanwhile, the average organization tests just 32% of its attack surface in a given year, leaving 68% completely unexamined. You can't hire your way out of that gap. Whatever you build or buy to close it will need a validation layer you can actually trust.

Watch On-Demand

Continue Exploring AI Pentesting and Risk Validation

See how Synack combines Sara AI Pentesting with the Synack Red Team to turn AI-scale findings into proof you can act on.

Product Tour

See Sara AI Pentesting in Action

Explore how Synack combines AI-driven reconnaissance and validation with human expertise to uncover real exploitable risk.

See Sara AI →
Free Trial

Start a Free Sara AI Pentesting Trial

Run a real AI-powered pentest on an approved target and validate exploitable risk faster.

Start free trial →
Blog

Why Continuous Security Validation Matters

Learn why leading organizations are moving beyond traditional pentesting toward continuous validation models.

Read the blog →
Frequently Asked Questions

AI-Enabled Offense, Proof, and the Harness FAQ

What did Tim Nordvedt cover in this session?+

Tim Nordvedt, Senior Manager of North America Solutions Architecture at Synack, covered three things: how frontier AI models have changed the threat landscape, what that means for organizational risk, and a practical framework for telling real agentic pentesting capability apart from repackaged automation.

Has AI really changed the threat landscape, or just the access to it?+

The vulnerabilities themselves haven't changed, the access curve to exploiting them has collapsed. The same pattern played out in 2004 when Metasploit put professional-grade exploits in reach of anyone; frontier models like Anthropic's Mythos and OpenAI's GPT-5.6 Cyber are repeating that shift at a much faster pace.

Why did only 75 of the 6,202 vulnerabilities Mythos found actually get patched?+

Of 6,202 high/critical findings, 1,752 were sent to independent reviewers, 62.4% were confirmed genuine, and only 75 were ultimately patched, about 1.2% of the total. The bottleneck wasn't remediation capacity, it was proof: teams could only act on findings they could independently validate and stand behind.

Why does "the harness" matter more than the model?+

Benchmark results show orchestration, decomposition, retries, and cross-checking drive performance more than the underlying model. Microsoft's 100+ agent MDash system beat a solo frontier model on the CyberGym benchmark using the same class of models deployed differently, evidence that a vendor's engagement methodology matters more than which model they license.

What accuracy and guardrail standards do security leaders expect from AI-driven testing?+

In Synack and Omdia's State of Agentic AI Pentest survey, security leaders set roughly an 85% accuracy bar. 93% said guardrails are critical or important, 58% require transparent, explainable AI decision-making, and 54% require industry certifications as standard.

How does CISA's Binding Operational Directive 26-04 affect remediation timelines?+

BOD 26-04, issued in June, replaces a flat remediation deadline with a five-tier risk model for federal civilian agencies, requiring fixes in as little as three days for known-exploitable, fully automated, total-system-control vulnerabilities. CISA explicitly encourages private-sector adoption, so this bar is likely to show up in audits, cyber insurance, and customer requirements within 12-18 months.

How does Synack combine AI with human researchers?+

Synack's approach pairs SARA (Synack Autonomous Threat Agent) for machine-speed recon, asset enumeration, and known-pattern detection with the 1,500+ researcher Synack Red Team for horizontal chaining, business-logic attacks, and judgment calls on ambiguous findings, an agent-led model with human oversight rather than either side working alone.

Extend SECTION SETTINGS - THIS ELEMENT WILL BE SHOWN ONLY IN THE CONTENT EDITOR

No video selected

Select a video type in the sidebar.