In Mythos testing a number of companies where doing what I call 'two way' testing. You have one set of agents attack the source code and another set attack the binary and running application. And see what exploits are found by each system. Then in a final round you have another set of agents compare both for weaknesses.
They can be really good at tool use and data gathering to find flaws.