Definition
Use of AI systems to continuously and autonomously execute authorized attack techniques against an organization’s own environment — ideally production — to find exploitable paths, guide remediation, and re-verify fixes without traditional human-led pentest cycles.
Key Points
- Distinct from unauthorized AI attackers; authorization and production safety are the product claims
- nodezero by horizon3 is a leading commercial example at unicorn-scale funding
- Complements ai-red-teaming of models and ai-agent-security runtime controls