Cybersecurity competition data released by Hack The Box reveals a striking shift in how leading practitioners approach digital security challenges. The 2026 Global Cyber Skills Benchmark Research Brief, which synthesizes three years of competitive data, demonstrates that artificial intelligence has moved from experimental territory into the core operational methods of the world's strongest security teams. While the technology remains a minority presence across the broader competitive landscape, its concentration among top performers signals a fundamental transformation in how elite cybersecurity professionals work.

The statistics paint a nuanced picture of AI's role in modern cybersecurity. AI agent accounts represent a mere 2.7 per cent of all registered accounts in Hack The Box competitions, yet this technology punches far above its numerical weight. Among the competition's top 25 teams, 17 of them—constituting 68 per cent—maintained at least one AI agent account. This disparity between overall prevalence and elite adoption suggests that experienced practitioners have recognised AI's value and incorporated it as a strategic tool rather than viewing it as peripheral to their work.

Quantifying AI's direct contribution to competitive success proves more complex. The AI agent accounts submitted 4.2 per cent of all flags—the successful solutions that demonstrate completion of security challenges—and earned 4.6 per cent of total points awarded. These figures reveal that while AI handles a measurable portion of the workload, the technology complements rather than replaces human expertise. Haris Pylarinos, Hack The Box Founder and Chief Executive Officer, cautioned against interpreting these metrics as proof of AI causation in competitive success. Instead, the data illuminates how AI has become woven into the operational fabric of elite teams, functioning as one element within a broader problem-solving ecosystem.

The broader competitive landscape has undergone dramatic transformation over the three-year period. Teams are now solving cybersecurity challenges at accelerated speeds, with the median time-to-solve declining from 26.1 hours in 2024 to just 13.8 hours in 2026. This represents a reduction of more than 12 hours—a substantial improvement that reflects both technological advancement and evolving human expertise. Even more striking, the number of teams completing the entire challenge board has increased sevenfold, from two teams in 2024 and three in 2025 to 15 teams in 2026. These performance gains suggest that the combination of AI-assisted tools and highly skilled practitioners is producing unprecedented levels of achievement.

The integration of AI into cybersecurity extends far beyond competitive contexts. Pylarinos emphasised a critical insight: as AI agents become more sophisticated and capable, human judgment, validation, and technical hands-on skills become more important rather than less. This counterintuitive observation contradicts fears that automation will diminish the human element in security work. Instead, the reality suggests that AI functions optimally when operated by practitioners with deep technical knowledge who can critically evaluate AI-generated suggestions, validate outputs against real-world security requirements, and recognise when AI systems operate outside their competency boundaries.

The dual-edged nature of AI in cybersecurity gained further prominence through recent incidents. Hugging Face's July 2026 incident disclosure and OWASP's Q1 2026 GenAI exploit roundup both demonstrate that artificial intelligence simultaneously creates new vulnerabilities and provides defensive capabilities. Threat actors are increasingly leveraging AI to enhance attack sophistication, generating novel exploitation techniques that human defenders must counteract. Concurrently, defenders employ AI-powered tools to identify threats, respond to incidents, and validate security controls. This arms race dynamic means that cybersecurity professionals must develop competency not just in using AI defensively but in understanding its potential malicious applications.

For security leaders across Southeast Asia and beyond, the implications extend beyond academic curiosity. Organisations implementing cybersecurity frameworks must now grapple with a shifting landscape where practitioners increasingly rely on AI tools. The challenge transcends simple technology adoption; it requires building teams capable of directing AI agents effectively, testing their outputs rigorously, and validating results before implementation. This human-centric approach to AI integration ensures that organisations leverage automation's efficiency while maintaining the critical thinking necessary for genuine security.

Hack The Box's earlier research explored controlled scenarios where practitioners deliberately worked with AI tools to understand performance impacts. The latest findings provide a complementary perspective, documenting what happens when experienced competitors freely choose their own methodologies. This shift from experimental conditions to real-world practice validates the hypothesis that AI is transitioning from novelty to necessity within elite cybersecurity circles. The self-selection bias evident in this data—that the strongest teams gravitate toward AI adoption—suggests the technology delivers genuine value to practitioners who know how to deploy it effectively.

The research trajectory outlined by Hack The Box reflects broader industry trends in technology integration. Organisations implementing cybersecurity upgrades increasingly cannot ignore AI capabilities, yet successful implementation requires more than simply deploying the technology. Human expertise in directing, evaluating, and validating AI-generated work has become a differentiator between organisations that successfully harness AI's potential and those that struggle with false positives, misaligned priorities, or security blind spots created by over-reliance on automated systems. The convergence of human skill and artificial intelligence represents not a replacement of expertise but an evolution of how expertise manifests in modern cybersecurity practice.