Analysis of 43 million enterprise assets finds AI-viable attack paths are twice as deep, persist longer and increasingly fall outside traditional security remediation priorities
SAN FRANCISCO, Oct. 8, 2026 /PRNewswire/ -- A new report from Cogent Security found that advances in AI are creating a growing class of enterprise attack paths that would be impractical for human attackers to pursue, but are viable for autonomous AI agents.
The report, Beyond the Human Horizon, analyzed 43 million assets and 1.2 billion vulnerability, misconfiguration and identity findings across the digital infrastructure of more than 50 Fortune 1000 organizations. The research found that in August 2026, the average enterprise picked up 45 new attack paths to crown jewel assets, including 11 viable for human attackers and 34 viable only for AI agents.
The findings show how AI changes which attack paths are practical to exploit. AI agents can continuously pursue longer, lower-yield attack paths across multiple security domains that human intrusion teams would be unlikely to attempt.
Key findings include:
"AI agents are creating attack paths that security teams have never had to worry about before," said Vineet Edupuganti, CEO and co-founder of Cogent. "For every new attack path a human attacker can realistically pursue, three more are emerging that only make sense for machines. They're longer, harder to see and often built from vulnerabilities that security teams have been told are low priority."
AI agents do not need new exploitation techniques to make these attack paths viable. Human attackers have limited time and tend to abandon paths that require too many steps or produce little value along the way. AI agents can keep going, operating continuously and in parallel across hundreds of instances. That makes longer and more complex attack paths practical to pursue.
The full Beyond the Human Horizon report, including analysis of attack path formation, depth, persistence and cross-domain visibility, is available here.
Methodology
Cogent Research analyzed 43 million assets and 1.2 billion vulnerability, misconfiguration and identity findings across the hybrid environments of more than 50 Fortune 1000 organizations.
Attack path analysis drew on an average of 12 data sources per organization, spanning vulnerability scanners, endpoint detection and response, identity providers, cloud service providers, firewalls and configuration management databases. Findings were normalized, deduplicated and joined into a graph of assets, identities and trust relationships for each environment.
An attack path was defined as a traversable sequence of hops from an initial foothold to a crown jewel asset, with each hop validated against the environment's actual configuration, permissions and controls. A path counted as new in the month its full kill chain became simultaneously present. Depth was scored across asset, action, privilege and boundary hops.
A path was classified as machine-viable when it exceeded at least one threshold of documented human intrusion economics covering depth, per-step yield or technique breadth. Thresholds were calibrated against published red team engagement data and DFIR incident reporting. Paths inside every threshold were classified as human-viable.
About Cogent
Cogent is an applied AI lab whose agents detect and fix security vulnerabilities faster than attackers can exploit them. The Cogent platform identifies exposure to new vulnerabilities within minutes, builds contextualized remediation plans, and executes fixes at whatever level of autonomy the customer allows, from human-approved to fully autonomous. Fortune 500 security teams using Cogent have reduced the exposure window for critical vulnerabilities by 97 percent. Built by researchers and operators from Google DeepMind, Abnormal Security, and Coinbase, Cogent is backed by Greylock Partners and Bain Capital Ventures. Learn more at cogent.com.
View original content:https://www.prnewswire.com/news-releases/34-new-attack-paths-open-up-at-the-average-enterprise-each-month-that-only-ai-agent-swarms-can-exploit-up-386-in-one-year-302902523.html
SOURCE Cogent Security