Definition

Use of AI systems to continuously and autonomously execute authorized attack techniques against an organization’s own environment — ideally production — to find exploitable paths, guide remediation, and re-verify fixes without traditional human-led pentest cycles.

Key Points

  • Distinct from unauthorized AI attackers; authorization and production safety are the product claims
  • nodezero by horizon3 is a leading commercial example at unicorn-scale funding
  • Complements ai-red-teaming of models and ai-agent-security runtime controls

Sources