Agentic AI testing: from faster commits to faster, safer releases
Agentic AI testing is the use of autonomous AI agents that can plan, execute, and adapt software tests or security checks across tools and environments, taking direct action through those tools rather than only suggesting code or commands to human operators. This shift matters because coding copilots boosted the rate of change without upgrading the safety rails around that change, and now testing agents are being designed to close that gap by owning repetitive work while keeping humans in charge of intent and judgment.
The story behind BrowserStack’s Test Companion and PortSwigger’s Burp AT is not another tale of smarter code completion; it is a reset of where AI sits in the software lifecycle. Coding agents already increased commits by 180%, while releases rose by only 30%, according to a 2026 NBER study. Testing—and the manual friction around it—is the missing link. Agentic AI testing and security testing agents promise to align commit velocity with release velocity by letting agents drive execution, not just suggestion. This is the start of AI as a workflow participant rather than as a glorified autocomplete.
Test Companion: automated test automation inside the IDE
BrowserStack’s new Test Companion is a clear statement that automated test automation belongs where developers live: inside the IDE. Built for QA teams and automation engineers, it accelerates test authoring, execution, debugging, and maintenance across web and mobile applications. Instead of bouncing between an editor, a browser farm, and test dashboards, teams work with one agentic AI testing harness that sits on top of their existing frameworks and infrastructure from day one, with no setup or context switching.
Test Companion does more than generate a few boilerplate assertions. It runs a complete test cycle in the IDE: it generates test cases, authors and executes scripts, debugs failures, and speaks directly to browsers and devices across functional, visual, accessibility, and API testing. It understands existing automation frameworks, page objects, helpers, and conventions, and validates on more than 30,000 real devices and browsers. This is automated test automation: instead of humans translating requirements into scripts and re‑fixing them every time the UI moves, the agent keeps tests alive. As BrowserStack’s CTO puts it, “Any AI that only writes tests solves the easy part. Test Companion owns the full cycle, and that’s the shift.”
Burp AT: security testing agents with hard boundaries
While Test Companion moves agentic AI into IDE testing tools, PortSwigger’s Burp AT moves it into frontline security testing workflows. Burp AT brings agentic AI to professional penetration testing, letting pentesters delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project context, and purpose-built pentesting capabilities. The key design choice is that autonomy is conditional: testers control how much work the agents perform, while Burp enforces scope, permissions, and approval rules.
This matters because models can now form hypotheses, act through tools, interpret how an application responds, and decide what to try next. That power is dangerous without constraints. Burp AT anchors security testing agents in Burp’s mature tooling layer, so agents use specialist web security tools rather than improvised HTTP scripts. Scope, tool access, and approval rules are enforced outside the model and are not instructions the model can reinterpret. Agents can propose actions, but they cannot execute anything Burp does not permit, and their activity is recorded alongside the rest of the engagement. In other words, Burp AT treats AI as a junior tester you supervise and audit, not a black box scanner you hope behaves.

From autocomplete to agents: the next layer of developer productivity
The common thread between Test Companion and Burp AT is a bet that IDE-native and purpose-built agentic tools are the next productivity layer after code completion. Test Companion extends BrowserStack’s suite of more than 20 agents across the testing lifecycle into the IDE, bringing agentic testing directly into existing workflows. Burp AT gives pentesters a specialist alternative to improvised stacks of coding agents, prompts, and scripts around the testing workflow. Both tools show that meaningful gains come when AI is wired into real workflows, not perched on the edge of them.
The practical impact is straightforward: QA teams use Test Companion to reduce the human grind of writing, debugging, and healing tests while validating against tens of thousands of real devices; security teams use Burp AT to hand off repetitive probing while keeping humans in charge of scope and findings. Agentic AI testing will not replace testers or pentesters; it will replace the repetitive, glue-code parts of their jobs. Teams that adopt these IDE testing tools and security testing agents early will ship faster with fewer blind spots. Teams that stay with manual, fragmented workflows will keep seeing a 180% spike in commits with only a 30% bump in releases—and an even smaller bump in confidence.






