“The beast needs a cage”: Why PortSwigger’s agentic pentesting is kept safe behind bars
The New Stack Adrian Bridgwater
PortSwigger released Burp AT, a public beta tool that brings agentic AI to professional pentesting while keeping agents constrained within human-controlled boundaries through a deterministic control layer. The system enforces scope, permissions, and approval rules, allowing pentesters to decide how much autonomy agents receive for each task, with all actions recorded and reversible. This approach represents a shift toward using AI agents for security testing while maintaining human oversight and preventing autonomous systems from operating beyond defined limits.
Why it matters
As agentic services diversify across the entire enterprise technology stack, the rise of agentic coding tools is being challenged by The post “The beast needs a cage”: Why PortSwigger’s agentic pentesting is kept safe behind bars appeared first on The New Stack.