Agentic AI security testing: what it is and why it matters
Agentic AI security testing is the use of autonomous or semi-autonomous AI agents that can plan, execute, and adjust penetration testing activities, combining reasoning over context with direct control of security tools to discover vulnerabilities and support human-led assessments across complex applications and infrastructure.
The headline story is simple: agentic AI is no longer a lab demo; it is now embedded in mainstream penetration testing workflows. PortSwigger’s public beta of Burp AT adds agentic AI straight into Burp Suite, bringing autonomous agents to professional penetration testing engagements. This shift arrives in a market forecast to reach $6.98 billion in value by 2032, driven by escalating threats. If security teams treat this as “just another scanner,” they will either miss its upside or lose control of how tests are run. The real question is not whether AI can find bugs—it can—but whether teams can govern how these agents operate on real targets.

How Burp AT changes automated penetration testing in practice
Burp AT is the clearest sign that agentic AI security testing is moving into everyday practice. It lets penetration testers delegate defined investigative tasks to AI agents that work through Burp Suite’s own tools, project context, and purpose-built pentesting capabilities. In other words, the model is not firing raw HTTP calls; it is driving the same tested workflows humans rely on. Models can do more than run predefined checks; they can form hypotheses, act through tools, interpret how an application responds, and decide what to try next. That turns AI from a static rules engine into an exploratory partner.
Control, however, does not disappear. Testers decide how much work the agents perform, while Burp enforces scope, permissions, and approval rules. Users can begin with tighter supervision and increase autonomy where agent performance, target sensitivity, and engagement rules justify it. This design makes Burp AT a Burp AT pentesting tool that supports AI security automation without handing the steering wheel entirely to the model.
AI security automation joins—not replaces—manual expertise
The rise of Burp AT does not mean manual hacking is obsolete; it signals a new hybrid era. Penetration testing has long combined “the expertise of experienced security professionals and the use of powerful penetration testing tools”. That mix is now tilting toward AI-assisted workflows. Tools like Astra already combine manual with automated penetration testing features for applications, networks, APIs, and blockchain, while Acunetix focuses on scheduled scans that can surface over 12,000 web application vulnerabilities.
Agentic AI slots into this landscape as the next layer of automated penetration testing. Instead of only running static test suites, agents can orchestrate tools, chain checks, and refine attacks mid-run. For pentesters who were hacking together their own coding agents and improvised agentic workflows, Burp AT offers a specialist alternative to homegrown integrations, prompts, and context wiring around the testing workflow. The message is clear: modern platforms will blend AI-assisted testing with traditional manual methods, and teams that ignore AI risk being outpaced by those who integrate it thoughtfully.

Governance, controls, and audit trails: the non‑negotiables
Agentic AI security tools are powerful, but without strong guardrails they are a compliance and safety headache. Security teams need more than clever models; they need enforceable limits. Burp AT gives a template for what good looks like. Pentesters can decide how much work agents take on for each task and engagement, and every action can be allowed, forced to seek approval, or blocked outright. Scope, tool access, and approval rules live in Burp’s tooling layer, which is architecturally separate from the model. That separation matters: it prevents the agent from redefining its own boundaries mid-test.
Equally important, agent requests and tool activity are recorded in the Burp project as testing progresses, giving pentesters a record to inspect alongside the rest of the engagement rather than relying only on the model’s account. For organizations under regulatory pressure, this kind of audit trail is not optional. Any evaluation of agentic AI security testing should put built-in controls and evidence capture ahead of flashy demo results.

What’s next for security teams adopting agentic AI
Agentic AI in penetration testing is a moving target, and security teams should plan for continuous change rather than a one-off rollout. Burp AT already includes structured, task-specific pentesting skills developed with PortSwigger Research. As that research group develops and validates new techniques, those approaches can be translated into skills that agents can apply during real tests. The tool itself will steadily grow more capable, which is both an opportunity and a governance challenge.
According to SNS Insider, “the penetration testing market is expected to reach $6.98 billion in value by 2032, largely due to the continued advancement of cybersecurity threats”. In a market scaling that fast, organizations that systematize AI security automation will gain speed and coverage, while those that bolt it on haphazardly will drown in false positives or audit issues. The pragmatic path forward is clear: treat agentic tools like Burp AT as strategic capabilities, build playbooks for how testers supervise them, demand strong controls and audit trails, and assume that AI-assisted testing will soon be the default, not the exception.






