Cybersecurity professionals are decisively faster at solving complex security challenges, with artificial intelligence agents now forming part of the standard operational toolkit among the world's leading security teams, according to fresh data from Hack The Box released in Kuala Lumpur. The platform's comprehensive 2026 Global Cyber Skills Benchmark Research Brief, drawing on three years of competitive performance data, charts a striking acceleration in both individual and team capabilities while documenting the expanding presence of AI-assisted workflows across the security profession.

The most striking finding concerns how AI adoption concentrates among the elite performers. Although accounts operated by AI agents represent only 2.7 per cent of all registered competitors on the platform, they appear within 17 of the top 25 competing teams—a penetration rate of 68 per cent. This disproportion proves telling. Those AI-operated accounts generated 4.2 per cent of all challenge solutions submitted and earned 4.6 per cent of total competition points. The pattern suggests that artificial intelligence tools have transitioned from novelty experimentation to embedded practice among practitioners operating at the highest levels of the discipline.

Haris Pylarinos, who leads Hack The Box as founder and chief executive, cautioned against interpreting the data as proof that AI directly causes superior performance. Rather, the evidence demonstrates that sophisticated security teams now routinely incorporate AI capabilities into their working methods, treating algorithmic agents as complementary assets to human expertise rather than replacements for it. This distinction matters significantly. The research indicates that AI appears predominantly alongside the strongest practitioners, not in their stead, suggesting that technical mastery and AI deployment reinforce one another rather than substitute.

The acceleration in solving capabilities has been dramatic across the entire competitive field. Median time required to solve challenges contracted sharply, falling from 26.1 hours in 2024 to just 13.8 hours in 2026—a reduction exceeding 12 hours in merely two years. This improvement reflects both technological advancement and deepening practitioner skill. Equally striking, the number of teams achieving complete challenge board solutions jumped from just two in 2024 and three in 2025 to fifteen in 2026. Such progression signals that the competitive baseline itself has shifted upward substantially, with success now requiring more rapid and comprehensive technical execution than previously.

For Malaysian and Southeast Asian security leaders, these trends carry immediate strategic implications. The region's cybersecurity workforce faces mounting pressure to absorb AI capabilities while maintaining the human judgment and validation protocols that prevent AI systems from introducing new vulnerabilities. Pylarinos emphasized that as AI agents become increasingly capable, the importance of human oversight actually intensifies rather than diminishes. Security leaders must ensure their practitioners possess not merely technical skills but the evaluative capacity to direct algorithmic work, test its outputs rigorously, and validate results against real-world requirements.

The broader security landscape increasingly mirrors this human-AI partnership model across both defensive and offensive dimensions. Recent high-profile incidents illustrate the dual-edged nature of AI in cybersecurity. Hugging Face's disclosure of a significant security incident in July 2026 and the Open Web Application Security Project's compilation of generative AI exploits during the first quarter of 2026 demonstrate that AI simultaneously creates new attack vectors and provides essential defensive capabilities. Organizations deploying AI tools without corresponding investment in skilled human oversight risk amplifying their exposure precisely when they intend to strengthen defenses.

The competitive data from Hack The Box provides a window into actual practitioner behavior when organizational constraints do not dictate tool choices. Unlike controlled laboratory environments that establish best-case scenarios for human-AI collaboration, competition participants select methodologies freely based on what they believe will maximize their success. That such overwhelming majorities of elite competitors have adopted AI agents suggests the technology has reached a maturity threshold where leading practitioners regard it as operationally necessary rather than experimentally interesting. This voluntary adoption pattern across the region's most skilled competitors signals the direction that broader industry practice will inevitably follow.

The research also illuminates how AI capabilities have shifted from theoretical promise to practical utility within specific security domains. Early HTB investigations examined performance improvements when practitioners explicitly incorporated AI into their work processes. The latest findings reveal where AI agents actually materialize when competitors operate under real competitive pressure without mandates regarding tool utilization. This transition from laboratory demonstration to genuine competitive deployment indicates that AI has fundamentally altered the practical skillset required for elite-level cybersecurity work.

For Malaysian organizations and security teams across Southeast Asia, the implications extend beyond competitive benchmarking into talent development and organizational capability planning. The convergence of AI adoption among top performers suggests that technical training programs must evolve to include not only traditional security domains but also practical experience directing, validating, and operationalizing AI-assisted security workflows. Security leaders cannot remain passive regarding AI adoption; they must actively develop their teams' capacity to work effectively alongside algorithmic systems while maintaining the critical judgment that distinguishes expert practitioners.

The evidence presented by Hack The Box ultimately reinforces a nuanced understanding of AI's role in cybersecurity. Algorithmic systems are becoming integral to how elite practitioners operate, yet human expertise remains not supplementary but foundational. The teams achieving greatest success combine AI capability with deep technical knowledge and rigorous validation discipline. For organizations seeking to strengthen their security posture, the challenge extends beyond acquiring AI tools to cultivating the human expertise necessary to deploy them judiciously and to validate their outputs against evolving threat landscapes and operational requirements.