Cybersecurity teams competing in Hack The Box's international challenges are demonstrating a marked shift in their approach to problem-solving, increasingly integrating artificial intelligence agents into their workflows while dramatically cutting the time needed to tackle complex security scenarios. According to HTB's 2026 Global Cyber Skills Benchmark Research Brief, which analysed trends across three years of competition data, this adoption pattern reveals not a wholesale replacement of human expertise but rather a complementary evolution in how modern security practitioners operate. The findings offer important insights for Malaysian and Southeast Asian organisations grappling with their own AI strategy in cybersecurity.

The data presents a compelling picture of where AI adoption is actually occurring within the competitive cybersecurity landscape. Though AI agent accounts represent just 2.7 per cent of all registered accounts across the platform, their concentration among top-performing teams is striking: 17 of the top 25 teams, or 68 per cent, deployed at least one AI agent. These agents contributed 4.2 per cent of all submitted solutions and earned 4.6 per cent of the total points awarded in the competition. Rather than suggesting that AI is driving superior performance across the board, the data indicates that leading practitioners are deliberately choosing to incorporate AI into their methodologies, treating it as one component of a broader technical toolkit rather than a silver bullet solution.

Haris Pylarinos, Founder and Chief Executive Officer of Hack The Box, emphasised that the research does not establish causation between AI deployment and improved team performance. Instead, he observed that artificial intelligence is appearing alongside some of the strongest practitioners, integrated into their existing expertise rather than replacing it. This nuance carries significant implications for organisations building cybersecurity strategies. As AI agents become increasingly capable, Pylarinos noted, the demand for human judgement, validation, and hands-on technical skill does not diminish—it intensifies. Security teams cannot simply implement AI tools and expect outcomes to improve; they must develop the competency to direct, challenge, and validate whatever an AI system produces.

The research underscores a fundamental transformation in how competitive cybersecurity challenges are being solved. Median time-to-solve has compressed dramatically over the three-year period, dropping from 26.1 hours in 2024 to just 13.8 hours in 2026—a reduction of more than 12 hours. Simultaneously, the number of teams capable of completing the entire challenge board has expanded significantly, rising from two teams in 2024 to three in 2025 and then 15 in 2026. This progression suggests that improvements in tooling, methodologies, and collective knowledge within the cybersecurity community are enabling faster and more thorough problem-solving, whether or not AI is directly involved. Yet the concentration of AI among top performers suggests these tools are being leveraged most effectively by those with existing mastery.

The emergence of AI within cybersecurity is, however, a double-edged phenomenon. HTB's research notes that AI is reshaping both the defensive and offensive sides of the security equation. Hugging Face's disclosure of a significant security incident in July 2026 and the Open Worldwide Application Security Project's (OWASP) first-quarter 2026 roundup of generative AI exploits demonstrate that artificial intelligence is simultaneously creating new vulnerabilities and becoming integral to how defenders must respond. As adversaries develop AI-powered attack methods, defensive teams require AI-augmented capabilities to keep pace. This dynamic creates a challenging landscape for security leaders, particularly in developing economies where resources for training and tool deployment may be constrained.

For Malaysian enterprises and regional organisations, this research provides valuable context for understanding where AI adoption in cybersecurity is headed. Rather than viewing AI as an optional enhancement or a speculative future capability, the evidence suggests that competitive advantage increasingly accrues to organisations that can effectively integrate AI into their security operations. However, this integration requires more than purchasing tools; it demands practitioners with sufficient foundational knowledge to recognise when AI is performing correctly, when it is hallucinating or making errors, and how to validate its recommendations before acting on them. This places enormous emphasis on human capital development, particularly the recruitment and retention of experienced cybersecurity professionals who can mentor newer team members.

The shift from experimentation to operational deployment is evident in how HTB's latest findings build upon earlier, more controlled research examining AI and cybersecurity performance. Where earlier studies placed practitioners in structured scenarios with AI tools available, the 2026 data reflects real-world choice—security professionals selecting their own approaches and electing to incorporate AI where they judge it beneficial. This migration from laboratory to production environments suggests that practitioners have moved beyond testing whether AI agents work and are now answering the more difficult question of how to integrate them effectively into live security operations. The trend is not universal; the majority of teams still do not employ AI agents, indicating that human-only approaches remain viable for many competitors.

However, the concentration at the top of the competitive rankings signals that experienced teams view AI as a legitimate performance enhancer when deployed thoughtfully. The data suggests these teams are not blindly trusting AI output but rather using AI agents to handle certain categories of work—potentially faster reconnaissance, initial analysis, or hypothesis generation—while reserving critical validation and decision-making for human experts. This division of labour between AI and human intelligence appears to be where genuine competitive advantage emerges. For security leaders in Malaysia and across Southeast Asia, the implication is clear: organisations that can build cultures where AI and human expertise work in tandem, rather than in competition, will likely outpace those taking a purist approach to either extreme.

The cybersecurity skills landscape itself is being reshaped by these trends. As AI agents become more capable and more widely adopted, the definition of core cybersecurity competency is evolving. Practitioners increasingly need to understand not only traditional security concepts—networking, cryptography, application security—but also how to work effectively with AI systems. This includes prompt engineering, understanding model limitations, recognising bias in AI outputs, and validating results before acting on them. For educational institutions and training providers across the region, this means curriculum development must accelerate to keep pace with industry needs. The rise in teams completing full challenge boards may reflect both better tools and better-trained practitioners, suggesting that investment in security education is paying dividends.

Looking ahead, the trajectory suggested by HTB's research implies that AI adoption in cybersecurity will likely continue expanding from the top tiers downward. As tools mature and become more user-friendly, teams with fewer expert practitioners may increasingly turn to AI to compensate for knowledge gaps or to handle routine analysis. This could democratise security capability, allowing smaller organisations to punch above their weight. Conversely, if AI tools amplify existing advantages for well-resourced teams with expert practitioners, they could widen the gap between security-mature and less-developed organisations. For Malaysia and other developing economies, actively managing this transition—ensuring that AI tools become vehicles for capability-building rather than further concentration of security expertise—should be a strategic priority. The stakes extend beyond corporate security to national cybersecurity posture and economic competitiveness in an increasingly digital world.