Every few weeks, another startup announces an AI pentester. Looking at the market, it feels as though the future of AI pentesting will come from a well-funded startup with access to the best models, researchers and compute.
That view overlooks pentesting boutiques. Talking with customers, I keep hearing the same thing: many are building their own AI pentesters, and some may already possess one of the most valuable assets in this market.
They may have years of HTTP traffic, testing notes and tool output linked to validated findings and final reports. The report shows what mattered. The underlying traffic shows how the testers got there. It contains the requests that led nowhere, the hypotheses that were rejected, the unusual responses that deserved more attention and the sequence of actions that eventually produced a vulnerability. Linked to severity decisions, report revisions and remediation outcomes, this may be the holy grail of pentesting training data.
Not every boutique will have retained this data, have permission to reuse it or have stored it in a usable format. Those that have may possess something that would be extremely expensive for a startup to recreate.
PTaaS and bug bounty platforms are also credible contenders. They have reports, remediation discussions, customer relationships and distribution, although their data is often stronger on the outcome than on the process that produced it.
Boutiques also have a learning loop that is already being funded. They perform real assessments every week, allowing them to introduce AI gradually, compare its work with experienced testers and automate one part of the process at a time. The customer pays for the engagement while the boutique improves its system.
AI startups begin from the opposite position. They need real targets, realistic environments and expert feedback. They may have to subsidise assessments or convince early customers to let an immature system test their applications.
More importantly, boutiques do not need full autonomy.
Automating the first, say, 80% of a pentest may be relatively straightforward. Crawling, endpoint discovery, standard checks, payload generation, evidence collection and report drafting are repetitive enough to benefit quickly from AI.
The difficulty is the last mile of pentest automation.
Automation does not progress linearly. Each additional percentage point becomes harder because the remaining work contains more ambiguity, unusual application behaviour, missing context and decisions that require judgment.
An AI startup may need to solve that last mile. Its economics depend on building something that scales like software rather than a consultancy with better internal tools. Investors are not funding it to make pentesters somewhat more productive. They expect growth that does not require adding another tester for every new group of customers.
For a boutique, the human in the loop is not a temporary failure of the product. It has always been the operating model.
A boutique can automate most of the repetitive work, leave the difficult edge cases to an experienced pentester and still transform its margins and capacity. The pentester can remain responsible for direction, validation, quality assurance and communication with the customer.
An agent that finds real vulnerabilities but still requires expert supervision may be disappointing for a venture-backed startup. For a boutique, it could already be transformative.
The problem for startups is that the last mile may take longer than expected. At the same time, every foundation-model improvement makes boutiques more productive while potentially commoditising parts of what an AI startup has built.
Startups do have an important advantage. A consultancy must continue paying testers when they are sitting on the bench. An AI company can reduce API usage, shut down compute or leave capacity unused at relatively little cost.
Boutiques may therefore have better economics for learning, while startups may have better economics for scaling once autonomy works.
The winners could come from several directions: an AI startup that reaches reliable autonomy, a platform that already owns the workflow or a boutique that combines historical data, real engagements and human supervision.
The mistake may be assuming that the winning AI pentesting company must look like an AI startup.
AI startups need to solve the last mile of pentest automation.
Pentesting boutiques only need to make their humans more productive.
Want to build these skills hands-on?
PentesterLab has 700+ real-world labs on web hacking, code review, and vulnerability analysis. Start with a free account.