# AI security testing gaps

> Live situation record from CLSTR: https://clstr.news/situations/ai-security-testing-gaps
> Updated: 2026-07-29T14:20:00.000Z. Sources: 5. Developments: 2.

A 2026 Synack survey of security leaders found that 95 % of firms discovered serious or critical AI‑related vulnerabilities outside regular penetration‑testing windows, exposing coverage, trust, and maturity gaps in their security programmes. Only 15 % described their testing as continuous, and 79 % said they would not act on AI‑generated results without human validation. At the Munich Cyber Tactics, Techniques and Procedures (MCTTP) conference, a five‑zone model was introduced to shift analysis from individual components to hidden attack paths linking AI agents, retrieval‑augmented generation systems and multi‑component platforms.

Later that month, a series of AI‑driven software failures caused widespread service outages in Japan, Australia, the United States, New Zealand and elsewhere, affecting payment networks, airline operations and cloud services. Despite the surge in AI‑identified flaws, a VulnCheck study of over a thousand such findings reported that only around 1.3 % were actually exploited, a rate comparable to traditional vulnerabilities. Together, the survey and outage reports illustrate persistent gaps in AI security testing and the limited translation of AI‑discovered flaws into real‑world attacks.

## Timeline

### 2026-07-29: AI-Driven Software Glitches Spark Outages but Exploited Vulnerabilities Remain Rare

AI-related software glitches caused outages in Japan, Australia, the US, and New Zealand, while a VulnCheck study shows only 1.3% of AI‑found vulnerabilities have been exploited, indicating limited cyber‑attack

2 sources. https://clstr.news/cluster/ai-driven-software-glitches-spark-outages-but-exploited-vulnerabilities-remain-rare

### 2026-07-24: Synack study finds 95% of firms miss critical AI flaws between pentests

Synack’s survey shows 95 % of firms miss critical AI vulnerabilities between scheduled pentests, highlighting coverage, trust and maturity gaps, while a new five‑zone model at MCTTP 2026 aims to map hidden AI‑t

3 sources. https://clstr.news/cluster/synack-study-finds-95-of-firms-miss-critical-ai-flaws-between-pentests

---
Cite as: AI security testing gaps. CLSTR, https://clstr.news/situations/ai-security-testing-gaps
