“Human attackers remain more effective at finding vulnerabilities in AI systems than automated red teaming systems.”