Cybersecurity professionals operating at the highest competitive levels are integrating artificial intelligence into their daily workflows, according to new research from Hack The Box, the prominent skills development platform based in Kuala Lumpur. The 2026 Global Cyber Skills Benchmark Research Brief, which tracks performance patterns across a three-year period, demonstrates that top-performing teams have embraced AI agents as complementary tools rather than replacements for human expertise. This shift represents a meaningful evolution in how the world's strongest cybersecurity practitioners approach complex technical challenges, with significant implications for how organisations across Southeast Asia should be structuring their security teams and training programmes.
The evidence of AI adoption among elite competitors is striking when examined closely. While AI agent accounts represent only 2.7 per cent of all registered participants in the competition, these tools appear far more frequently among teams ranked in the top 25, where 68 per cent of performers have integrated at least one AI agent into their operations. Yet despite this heavy presence at the highest levels, the contribution from AI systems remains proportional rather than dominant, accounting for just 4.2 per cent of submitted solutions and 4.6 per cent of awarded points. This distribution pattern suggests that AI functions as a productivity accelerant and analytical aid rather than as a substitute for the human judgment and technical knowledge that remains essential to solving cybersecurity problems.
Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, emphasised that the data does not suggest AI is the primary driver of superior performance. Instead, the research demonstrates that AI has become part of the standard toolkit deployed by many of the competition's strongest practitioners. The relationship appears symbiotic, with experienced professionals leveraging AI capabilities to enhance their own analytical work, test hypotheses more rapidly, and validate findings more comprehensively. This pattern aligns with broader trends in technology industries where human-AI collaboration outperforms either working in isolation, though the cybersecurity domain presents unique challenges in terms of validation and accuracy.
Measurable improvements in competition performance have accelerated noticeably over the past three years, with timing metrics showing particularly dramatic shifts. The median time required to solve challenges has contracted by nearly 12 hours, dropping from 26.1 hours in 2024 to just 13.8 hours in 2026, representing a reduction of approximately 47 per cent. This compression of problem-solving timescales reflects both the maturation of practitioner skills and the efficiency gains that AI-augmented workflows provide. Simultaneously, teams are achieving more comprehensive results, with the number of competitors completing the entire challenge board expanding from only two teams in 2024 to three in 2025 and reaching 15 in 2026, a sevenfold increase that indicates substantially broader capability across the competitive field.
The cybersecurity landscape has become increasingly complex, with AI creating risks alongside opportunities on both the defensive and offensive sides of the equation. Hugging Face's disclosure of a security incident in July 2026 and the Open Web Application Security Project's Q1 2026 roundup of generative AI exploits both underscore that artificial intelligence tools are simultaneously generating novel attack vectors while becoming essential to defensive operations. This dual reality creates a layered challenge for security leaders, who must not only adopt AI to remain competitive but also anticipate the new vulnerabilities that increasingly sophisticated AI-powered attacks might introduce into their organisations' threat surfaces.
For Malaysian companies and Southeast Asian enterprises seeking to strengthen their cybersecurity posture, the research carries crucial implications about talent development and team composition. The findings suggest that organisations cannot simply deploy AI tools and expect performance improvements; rather, they must invest in developing practitioner expertise to effectively direct, test, and validate AI-generated output. Security leaders must recognise that the human element becomes more critical, not less critical, as AI capabilities expand. Teams need to include individuals who can critically evaluate AI recommendations, understand the reasoning behind algorithmic suggestions, and possess sufficient technical depth to identify when AI systems might be providing plausible but incorrect answers.
The transition from controlled experimentation to real-world integration has become increasingly apparent through HTB's longitudinal research programme. Earlier benchmark studies examined what happens when practitioners deliberately work with AI, establishing baseline understanding of human-AI collaboration in cybersecurity contexts. The latest data set, drawn from open competitions where participants freely choose their own tools and approaches, provides a window into organic adoption patterns across the competitive community. This distinction matters significantly because it reflects genuine preference and pragmatic utility rather than imposed conditions, suggesting that practitioners have evaluated AI tools and determined they provide genuine value in their operational workflows.
The broader pattern emerging from this research indicates that AI is transitioning from experimental status within cybersecurity teams toward becoming embedded in standard operating procedures among leading practitioners. This evolution mirrors historical technology adoption cycles where innovative tools gain credibility through visible success at elite levels before spreading more widely. For regional organisations, this suggests that waiting passively for AI adoption to become commonplace may represent a missed opportunity, as first-movers who develop robust AI governance and validation frameworks may establish competitive advantages in threat detection, incident response, and vulnerability management.
The research also highlights an important distinction that security leaders should internalise: the presence of AI in security operations does not diminish the requirement for skilled practitioners. Instead, it elevates the importance of hiring individuals who can think critically about algorithmic outputs, possess strong foundational knowledge in cybersecurity, and can exercise mature judgment about when to trust versus scrutinise AI recommendations. This insight should shape hiring practices, training investments, and team-building strategies across Malaysian and Southeast Asian organisations as they modernise their security capabilities for an AI-augmented threat landscape.
