Analysis of 43 million enterprise assets finds AI-viable attack paths are twice as deep, persist longer and increasingly fall outside traditional security remediation priorities
SAN FRANCISCO, Oct. 8, 2026 /PRNewswire/ — A new report from Cogent Security found that advances in AI are creating a growing class of enterprise attack paths that would be impractical for human attackers to pursue, but are viable for autonomous AI agents.
The report, Beyond the Human Horizon, analyzed 43 million assets and 1.2 billion vulnerability, misconfiguration and identity findings across the digital infrastructure of more than 50 Fortune 1000 organizations. The research found that in August 2026, the average enterprise picked up 45 new attack paths to crown jewel assets, including 11 viable for human attackers and 34 viable only for AI agents.
The findings show how AI changes which attack paths are practical to exploit. AI agents can continuously pursue longer, lower-yield attack paths across multiple security domains that human intrusion teams would be unlikely to attempt.
Key findings include:
- Three new machine-viable attack paths appear for every human-viable one. In August 2026, 34 new attack paths viable for AI agents opened up at the average enterprise compared with 11 viable for human attackers. Machine-viable path formation increased 386% year over year, while human-viable path formation increased 38%.
- Machine-viable attack paths run at least twice as deep. The median machine-viable path crossed eight assets compared with four for human-viable paths, and five trust boundaries compared with two. The median machine-viable path also spanned five distinct technique domains, while 64% spanned four or more.
- 83% of machine-viable attack paths persist for more than 30 days. By comparison, 55% of human-viable paths remained in an environment for more than 30 days. Many machine-viable paths rely on medium and low severity vulnerabilities, configuration weaknesses and identity conditions that fall below traditional remediation thresholds.
- Low and medium severity vulnerabilities can combine into critical attack paths. Seven percent of critical paths in Cogent’s dataset were created entirely by chaining low and medium severity vulnerabilities, ones that are typically not prioritized for remediation.
- 64% of attack paths cross security domains that no single tool can see. Attack paths commonly move between endpoint, identity, network and cloud infrastructure. Reconstructing the median critical path required Cogent to correlate data from five different security tools.
“AI agents are creating attack paths that security teams have never had to worry about before,” said Vineet Edupuganti, CEO and co-founder of Cogent. “For every new attack path a human attacker can realistically pursue, three more are emerging that only make sense for machines. They’re longer, harder to see and often built from vulnerabilities that security teams have been told are low priority.”
AI agents do not need new exploitation techniques to make these attack paths viable. Human attackers have limited time and tend to abandon paths that require too many steps or produce little value along the way. AI agents can keep going, operating continuously and in parallel across hundreds of instances. That makes longer and more complex attack paths practical to pursue.
The full Beyond the Human Horizon report, including analysis of attack path formation, depth, persistence and cross-domain visibility, is available here.
Methodology
Cogent Research analyzed 43 million assets and 1.2 billion vulnerability, misconfiguration and identity findings across the hybrid environments of more than 50 Fortune 1000 organizations.
Attack path analysis drew on an average of 12 data sources per organization, spanning vulnerability scanners, endpoint detection and response, identity providers, cloud service providers, firewalls and configuration management databases. Findings were normalized, deduplicated and joined into a graph of assets, identities and trust relationships for each environment.
An attack path was defined as a traversable sequence of hops from an initial foothold to a crown jewel asset, with each hop validated against the environment’s actual configuration, permissions and controls. A path counted as new in the month its full kill chain became simultaneously present. Depth was scored across asset, action, privilege and boundary hops.
A path was classified as machine-viable when it exceeded at least one threshold of documented human intrusion economics covering depth, per-step yield or technique breadth. Thresholds were calibrated against published red team engagement data and DFIR incident reporting. Paths inside every threshold were classified as human-viable.
About Cogent
Cogent is an applied AI lab whose agents detect and fix security vulnerabilities faster than attackers can exploit them. The Cogent platform identifies exposure to new vulnerabilities within minutes, builds contextualized remediation plans, and executes fixes at whatever level of autonomy the customer allows, from human-approved to fully autonomous. Fortune 500 security teams using Cogent have reduced the exposure window for critical vulnerabilities by 97 percent. Built by researchers and operators from Google DeepMind, Abnormal Security, and Coinbase, Cogent is backed by Greylock Partners and Bain Capital Ventures. Learn more at cogent.com.
View original content:https://www.prnewswire.com/news-releases/34-new-attack-paths-open-up-at-the-average-enterprise-each-month-that-only-ai-agent-swarms-can-exploit-up-386-in-one-year-302902523.html
SOURCE Cogent Security
