The public argument is still stuck on whether generative AI belongs in security testing. That argument is a distraction, because the people causing the damage are not waiting for it to be settled. They are already using it, with no structure around it, and the results are going out to clients.
Point a model at an engagement with nothing enforcing rigor and it will produce volume — plausible findings, confident severity ratings, remediation advice, and a substantial amount that is simply not true. An engineer who cannot tell the difference passes it straight through. The client gets a longer report and a worse test.
That is where the false positives come from, and it is why so many buyers have concluded that AI-assisted testing is noise. They are drawing a fair conclusion from real evidence. They have just never been shown the other version.
Because used correctly, it is the largest coverage gain this work has ever had, with an experienced engineer deciding what any of it means. Used incorrectly, it is a false-positive generator with excellent grammar. Nothing on the outside of a report tells you which one you paid for.
That is the gap this credential closes. Not whether they used AI — whether they are any good at it.