The new Burp AT beta reflects a growing effort to integrate AI into professional cybersecurity while keeping experienced testers responsible for oversight, judgment, and decision-making.
PortSwigger has introduced the public beta of Burp AT, a new addition to its Burp Suite platform that brings agentic AI into professional web application security testing. Rather than positioning artificial intelligence as a replacement for human expertise, the company has designed the system to work alongside penetration testers, allowing them to determine how much responsibility AI agents assume during an engagement. The launch reflects a broader shift in cybersecurity toward AI-assisted workflows that emphasize collaboration instead of full automation.
The announcement comes as advances in large language models have demonstrated an increasing ability to identify software vulnerabilities and reason through technical problems. Yet translating those capabilities into professional security work introduces new challenges around trust, oversight, and accountability. PortSwigger’s approach focuses on keeping experienced testers in control by enforcing testing scope, permissions, and approval rules through Burp Suite itself, rather than relying on the AI model to follow instructions on its own. This architectural separation is intended to ensure that agents cannot exceed the boundaries established for a particular assessment.
Unlike general-purpose AI tools that depend on custom prompts or external integrations, Burp AT is built directly into Burp Suite’s established testing environment. The system allows AI agents to access project context, including previously collected traffic, discovered issues, and application structure, while using specialized security testing tools developed over more than two decades. PortSwigger has also incorporated structured penetration testing skills that can be updated as new research and testing techniques emerge, creating a more standardized way for AI agents to apply established methodologies during security assessments.
The platform also illustrates a growing recognition that AI’s value in cybersecurity depends as much on execution as reasoning. Professional penetration testing often requires handling malformed requests, navigating unusual application behavior, and documenting findings in a way that supports later analysis. Burp AT records agent activity alongside the rest of a project’s evidence, allowing testers to review every action rather than relying solely on the model’s explanations of what it did.
As organizations continue exploring AI-assisted security workflows, products like Burp AT suggest that the industry’s immediate direction is less about autonomous systems replacing specialists and more about augmenting experienced professionals with tools that can accelerate investigation while preserving human judgment. That balance may prove essential as AI becomes an increasingly common part of cybersecurity practice.