Cybersecurity professionals are solving high-stakes technical challenges with remarkable speed as artificial intelligence becomes embedded in the workflows of elite security teams, according to research released by Hack The Box, a leading cyber-skills training platform. The 2026 Global Cyber Skills Benchmark Research Brief, drawing on three years of performance data, reveals a clear trend: practitioners at the highest levels of the field are integrating AI agents into their problem-solving arsenal, yet this shift reflects evolution rather than replacement of human expertise.

The adoption patterns uncovered in the study present a nuanced picture of how AI is transforming professional cybersecurity. While AI agent accounts constitute merely 2.7 percent of all registered accounts on the platform, their concentration among top performers is striking. Seventeen of the top 25 competing teams—representing 68 percent of elite competitors—deployed at least one AI agent. These agents contributed 4.2 percent of all submitted flags and earned 4.6 percent of points awarded during competitions. The disparity between the tiny share of AI accounts and their prevalence among champions suggests that access to advanced tools alone does not drive success; rather, sophisticated teams are deliberately choosing to integrate these capabilities into their existing methodologies.

Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, emphasizes that the data reveals an important distinction often missed in AI discourse. "Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them," Pylarinos stated. "As agents become more capable, human judgement, validation and hands-on technical skill become more important, not less." This observation carries significant implications for organizations across Malaysia and Southeast Asia investing in cybersecurity capabilities. The message suggests that acquiring AI tools without building underlying human expertise represents a misguided strategy, whereas teams combining technological advantage with skilled personnel gain genuine competitive edge.

The performance improvements documented across the competition are substantial and measurable. The median time required to solve challenges has contracted dramatically over the three-year period examined in the research. In 2024, teams required an average of 26.1 hours to resolve problems; by 2026, this figure had fallen to 13.8 hours—a reduction exceeding 12 hours or nearly 47 percent. Beyond speed improvements, the research captures a more comprehensive shift in capability: only two teams completed the entire challenge board in 2024, three teams achieved this in 2025, and the figure jumped to 15 teams in 2026. These metrics suggest practitioners are not simply working faster but developing greater comprehensive mastery of cybersecurity domains.

The mechanisms driving these performance gains remain complex. While the correlation between AI adoption and superior results is evident, establishing causation requires careful interpretation. HTB's researchers have explicitly cautioned against assuming that AI directly causes improved performance, preferring instead to characterize the relationship as demonstrative of how sophisticated practitioners are integrating available tools into established workflows. This methodological restraint reflects scientific rigor but also acknowledges that numerous factors beyond tool selection—team composition, prior experience, training investment, and problem-solving methodology—contribute to outcomes in competitive environments.

The emergence of AI throughout cybersecurity presents a dual-edged transformation affecting both attackers and defenders. Recent security incidents underscore this complexity. Hugging Face's July 2026 incident disclosure and the Open Web Application Security Project's Q1 2026 GenAI exploit roundup both demonstrate that artificial intelligence is simultaneously expanding the attack surface available to adversaries while becoming integral to defensive strategies. This reciprocal escalation means organizations cannot simply adopt defensive AI without considering evolving threats posed by AI-powered attacks. For security leaders in Malaysia's growing technology sector and across Southeast Asia, this dynamic demands continuous reassessment of threat landscapes and capabilities.

The implication for regional cybersecurity professionals and organizations is straightforward yet demanding: AI competency is transitioning from experimental advantage to baseline expectation in advanced security roles. Teams that dismissed AI capabilities two years ago may find themselves operating at significant disadvantage compared to peers who have integrated these tools thoughtfully. However, this transition should not prompt panic-driven adoption without strategic planning. Rather, organizations should evaluate how AI agents can augment their specific operational needs while simultaneously ensuring that practitioners develop judgment and validation skills necessary to evaluate AI-generated outputs critically.

HTB's latest findings build upon earlier research the platform conducted examining AI performance in controlled benchmark environments. That earlier study explored what occurred when practitioners worked collaboratively with AI systems under experimental conditions. The current research provides complementary insight by examining where AI agents naturally appear when competitors operate freely and can select their own approaches. This shift from controlled experimentation to organic adoption patterns offers a more realistic window into how professional cybersecurity is actually evolving in practice.

For practitioners across Malaysia, the trajectory outlined by this research suggests that AI literacy and integration skills are becoming professional necessities rather than optional specializations. Security teams competing for resources, talent, and recognition within global markets will increasingly struggle without demonstrable AI competency. However, organizations must resist the temptation to view AI as a substitute for building strong human technical foundations. The research consistently points toward a future where the most capable security professionals are those who understand both the power and limitations of AI systems and can direct their application toward meaningful security outcomes.

The research ultimately provides strategic guidance for how organizations should approach AI integration in cybersecurity. Rather than asking whether teams should adopt AI—the answer increasingly appears to be yes—the more sophisticated question concerns how to integrate these capabilities while maintaining and strengthening the human judgment, technical depth, and validation rigor that remain the foundation of effective security work. For Malaysia's cybersecurity workforce and the broader Southeast Asian region, this study signals that the competitive frontier is shifting toward practitioners who combine technological sophistication with human expertise and critical thinking.