PortSwigger has released a public beta of Burp AT, an AI tool built for professional penetration testing that keeps autonomous actions strictly limited.
Agents propose, humans enforce
The system allows AI-driven agents to suggest investigative steps within Burp Suite, PortSwigger’s web security testing platform. Every action must pass through a control layer that enforces scope, tool access, and approval rules before execution. Pentesters set the boundaries, review proposals, and draw conclusions.
Dafydd Stuttard, creator of Burp Suite and CEO of PortSwigger, described the approach as a necessary balance. “We want the model’s pentesting creativity, but the beast needs a cage: agents propose, Burp enforces, and the pentester decides. This technology cannot self-govern, and you cannot prompt your way to assurance.”
Stuttard, who has worked in software security for over twenty years, cited a key moment in development. James Kettle, PortSwigger’s director of research, showed an early version that uncovered new behavior on live targets—while also demonstrating it could stray from its assigned scope without warning. “The reasoning was too powerful to dismiss, and far too unpredictable to govern itself,” Stuttard said.
From research to repeatable testing
Burp AT works with Burp Suite’s existing tools, letting agents pursue defined investigative tasks using context from the project codebase. Agents use context from the Burp project—traffic logs, target structures, and previously found issues—to build on shared knowledge.
PortSwigger has also turned validated testing techniques into structured “skills” that agents can apply without requiring users to rebuild methodologies through prompts or scripts. “The methodology behind genuinely novel discoveries can be encoded, not merely documented,” Stuttard said.
Related: AI workflows get native payment support
The system isn’t meant to replace pentesters but to let them assign specific tasks while keeping oversight. Users start with strict supervision, approving every action, then adjust as needed.
This approach reflects a common challenge in enterprise AI: balancing the speed and creativity of autonomous agents with control over high-stakes operations. In cybersecurity, where a single mistake can expose data or disrupt systems, the risks are especially high. PortSwigger’s solution—layering strict controls over AI—offers one way to manage that risk.
Stuttard noted that trust depends on the surrounding infrastructure, not just the AI. “Trust comes from professional tools, methodology, and enforced boundaries,” he said. That principle shapes the product’s design: pentesters remain responsible for scope, judgment, and conclusions, and every action is recorded in the Burp project.
The release arrives as agentic AI tools spread across enterprise technology. The same adaptability that makes these tools useful also makes them unpredictable. For now, PortSwigger’s solution keeps the system in check, allowing suggestions but never action without approval.
Teams already using Burp Suite can test the beta to see how autonomous agents fit into their workflows.
