A survey of 158 security practitioners by Pentest-Tools.com reveals that AI-assisted pentesting tools are creating a validation backlog rather than saving time. 87.8% of respondents said AI-generated findings required significant manual validation, and nearly 30% of free-text frustrations cited false positives, hallucinated exploits, or fabricated CVEs. One practitioner reported 250 of 300 AI-generated findings were junk. Only 20.3% of teams had workflows to handle 500+ findings from a single engagement. AI usage is highest in scanning and report writing but drops sharply in phases requiring live judgment like exploitation and lateral movement. Business logic flaws remain a consistent blind spot for AI tools. Meanwhile, 75.3% of practitioners already test AI-powered or LLM-integrated applications, and stakeholder pressure for more frequent testing is rising. Testing cadence — not org size — emerged as the strongest predictor of a team's ability to cope with AI-generated volume.