Skip to content
← Learn

AI + offensive

AI-assisted pentesting

What AI can do in a real pentest and what it cannot: acceleration with a human gate. The difference between automating reconnaissance and automating judgment.

The whole industry sells “AI pentesting” and almost nobody explains what the AI does. Here is the honest version: AI is good at sweeping surface, enumerating and proposing attack paths; it is bad at deciding when breaking something is worth it and at answering for consequences. That is why the model that works is hybrid: agents propose, people authorize and sign.

What AI does in a real engagement

Continuous recon of the external surface. Enumeration of subdomains, services and versions. Correlation of findings into candidate attack paths. PoC drafts the specialist validates and adjusts. That is a coverage multiplier: the specialist spends time on judgment, not re-walking what the agents already enumerated.

What AI does not do — and why it must not

It does not decide what enters scope. It does not run an intrusive action without human authorization. It does not interpret business impact: a SQLi in a marketing panel does not weigh the same as one in the payment processor. And it does not sign: the report is signed by the supervising person, because accountability is not delegated to a model.

Telling marketing from method

Ask two things: who authorizes each intrusive action, and what happens when the AI is wrong. If the answer is “the platform has guardrails”, demand to see them in writing. The explicit human gate is the difference between acceleration and theatre. For the direct contrast with the purely automatic approach: PTAI vs automated pentest. To bring it to your context: #contacto.

Straight answers

Does AI replace the pentester?

No. It accelerates reconnaissance, enumeration and PoC generation; it does not sign authorizations or carry accountability. Judgment —what to exploit, what to report, what to leave out— stays with a person who answers for the work.

What does the client gain from an AI-assisted pentest?

Wider coverage in the same window and findings with more context, because agents sweep more surface while the specialist spends time on what requires judgment. The delivery window is fixed in the contract; AI does not promise it, it makes it possible.

What risk does AI introduce into an engagement?

If it runs without a gate, the risk is acting out of scope or against forbidden targets. That is why every intrusive action from the platform passes explicit human authorization and gets logged. AI proposes; a person disposes.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn