But cyber protection has many distinct practices and sub-disciplines, so where will agentic autonomy continue to rise next?
Aiming to put agentic AI control into the realm of pentesting is PortSwigger, a company known for its web security testing platform, Burp Suite. The company released the public beta of Burp AT on Wednesday, a new product to bring purpose-built agentic AI to professional pentesting in Burp Suite.
Pentester-in-the-loop
The company’s pentesting agents can pursue defined investigative tasks using Burp Suite’s tools aligned to “relevant context” from the project codebase; in other words, pentesters decide how much work agents take on, while Burp enforces scope, permissions and approval rules.
The pentester remains responsible for scope, judgment and conclusions, so can we put our faith in this approach in the cauldron of live production code environments?
Dafydd Stuttard, Burp Suite creator and CEO of PortSwigger, tells The New Stack that “trust does not come from simply trusting the model” in this space. He insists that it comes from the professional “tools, methodology and enforced boundaries” around the model.
“We want the model’s pentesting creativity, but the beast needs a cage: agents propose, Burp enforces, and the pentester decides,” Stuttard says. “This technology cannot self-govern, and you cannot prompt your way to assurance.”
“We want the model’s pentesting creativity, but the beast needs a cage: agents propose, Burp enforces, and the pentester decides. This technology cannot self-govern, and you cannot prompt your way to assurance.”
A separate deterministic control layer
Stuttard explains that Burp AT is “governed by default” so that whenever agents request an action, it passes through a separate deterministic control layer where scope, tool access and approval rules are enforced, while requests and tool activity are recorded in the Burp project.
A software security consultant by trade, Stuttard has acted as founder and “chief swig” at PortSwigger for over two decades. Despite the length of this tenure, he can still pinpoint when the penny dropped about what the company has built for the agentic era.
Too powerful to dismiss, too unpredictable to self-govern
“The defining moment for me was seeing director of research at PortSwigger James Kettle’s system discover genuinely novel behavior on live, authorized targets, while also showing that it could change target without being asked,” Stuttard says. “That demonstrated both halves of the product truth at once: the reasoning was far too powerful to dismiss, and far too unpredictable to govern itself.”
For pentesters already experimenting with coding agents and improvised agentic workflows, Stuttard and team describe Burp AT as a “specialist alternative” to assembling and maintaining integrations, prompts, context and controls around the testing workflow.
We know that AI models can now do more than run predefined checks, i.e., they can form hypotheses, act through tools, interpret how an application responds, and decide what to try next. But the PortSwigger view is that using that capability professionally means agents also need reliable execution, relevant engagement context, structured testing methodology and boundaries they cannot reinterpret or bypass.
“The methodology behind genuinely novel discoveries can be encoded, not merely documented.”
Stuttard says that the work carried out to build this product has shown that the “methodology behind genuinely novel discoveries can be encoded”, not merely documented.
“Skills let us turn validated techniques into structured, reusable approaches that agents can apply through Burp, rather than asking every pentester to reconstruct the method themselves. That creates a much more direct route from research breakthrough to repeatable testing,” he adds.
In terms of real-world operational use, what the pentesting agents here can achieve depends heavily on the tools and context they work with. Burp AT enables agents to work natively through Burp Suite’s web security tools, rather than relying on general-purpose HTTP libraries or improvised integrations.
Maneuvring around malformed requests & message manipulation
Built against two decades of exposure to real applications, Burp agents are said to be able to “reliably handle malformed requests”, message manipulation and protocol edge cases that professional web security testing often demands.
Agents can also draw selectively on relevant information already held in the Burp project, including traffic, target structure, issues and discoveries gathered throughout the engagement. They can add to that shared context as they work, enabling later investigations to continue from what is already known rather than beginning again from a blank prompt.
Burp AT includes structured, task-specific pentesting skills developed with PortSwigger Research. These give agents reusable testing approaches without requiring every user to construct and maintain the methodology through prompts, scripts, and workflow instructions.
The skills also create a route from research to repeatable testing. As PortSwigger Research develops and validates new techniques, those approaches can be translated into skills that agents can apply during real tests.
Start slow, then increase pentest autonomy
Burp AT allows pentesters to choose how much work agents take on for each task and engagement. Actions can be allowed to proceed, configured to require approval, or blocked. Smart approvals allow routine work to continue while escalating decisions that need the pentester’s attention.
Software engineers can begin with tighter supervision and increase autonomy where agent performance, target sensitivity, and engagement rules justify it. The existing Burp tools remain available whenever the pentester wants to take over directly.
Competitors in the agentic pentesting space might feature unusual suspects including: Hadrian with its autonomous external attack surface exposure validation platform; Reflectiz with its Offensive Hub tool for agentic penetration testing for web applications; Horizon3 with its internal, external, cloud and Kubernetes autonomous penetration testing offerings; Xbow for AI-native autonomous penetration testing; Escape with its Cascade platform and Beagle Security, again for AI-powered continuous pentesting for web applications.
Time to shift pentesting (and the port) left
If PortSwigger gains kudos for this launch, then perhaps the company will start talking about a defining moment where agentic pentesting shifts application testing and analysis left. Given that Port (the drink) is always passed to the left, it feels like the company is missing out on a branding trick here.
According to Gentleman’s Journal, Port is never passed across the table or back on itself – it’s only to the left because in the British Royal Navy, the rule was “port to port,” i.e., “all the way around,” so expect that on a tech trade show t-shirt soon.
YOUTUBE.COM/THENEWSTACK
Tech moves fast, don’t miss an episode. Subscribe to our YouTube
channel to stream all our podcasts, interviews, demos, and more.