When agents do the testing and humans do the coordinating, who’s actually accountable for the findings?

That’s the question we explored in Super Cyber Friday: Hacking Pentesting in the Age of Agentic AI.

Sprocket CTO Eric Sheridan joined Will Gregorian, CISO at Galileo Medical, and CISO Series host David Spark for a thoughtful discussion on what agentic testing actually changes and what it doesn’t.

Topics covered:

  • What “human oversight” really means when agents are running autonomously and when oversight becomes the bottleneck
  • How to maintain accountability when a finding comes from a decision no human explicitly approved
  • How to build responsible AI into an offensive security product without sacrificing speed
  • What real validation of an AI pentesting agent looks like
  • Whether agentic pentesting changes the conversation security has with the business or simply accelerates it

If you’re running a pentest program, evaluating AI-powered security tools, or trying to understand where human judgment still needs to be in the loop, this recording is worth your time.