VYPR
researchPublished Jul 28, 2026· 1 source

PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing

PortSwigger introduces Burp AT, a public beta feature for Burp Suite Professional, enabling penetration testers to delegate tasks to AI agents while maintaining human oversight.

PortSwigger has officially launched Burp AT in public beta, integrating agentic AI capabilities into Burp Suite Professional. This new feature empowers penetration testers to delegate specific investigative tasks to AI agents, a move that allows them to retain full control over the scope, judgment, and final conclusions of their work. This development signifies a notable shift in the methodology of professional web application security testing, addressing the growing industry question of AI's trustworthiness in professional security contexts where accountability and reliability are paramount.

Burp AT is built upon four core principles designed to ensure the viability of agentic testing in real-world engagements. Firstly, the AI agents leverage Burp's existing tooling and project data, including captured traffic, target structure, and prior findings, rather than starting from scratch. Secondly, a curated library of specialized penetration testing skills provides agents with structured methodologies, supplementing general AI knowledge. These skills are continuously updated as PortSwigger's researchers develop new techniques. Thirdly, testers can adjust the autonomy levels of the agents, dictating which tasks can be executed independently, which require approval, and which are entirely off-limits.

Crucially, the fourth pillar of Burp AT's architecture is that all operational boundaries are enforced by Burp's underlying tooling layer, not by the AI model itself. This ensures that every action taken by an agent is meticulously logged, and agents are prevented from bypassing restrictions, even if they propose such actions. This design philosophy underscores PortSwigger's commitment to a workflow where AI agents propose actions, Burp Suite enforces the defined limits, and the human tester makes the ultimate decisions.

During closed beta testing, the practical benefits of Burp AT became evident. In one instance, a penetration tester utilized the tool to analyze 66,000 lines of minified JavaScript within a four-day engagement, a task that would be practically impossible to complete manually within such a timeframe. The AI agent successfully reconstructed endpoints and workflows from the obfuscated code, identifying suspicious, unauthenticated areas for further human scrutiny. This process ultimately uncovered a critical vulnerability that might have otherwise gone undetected for an extended period.

The experience was described by the tester as transformative, significantly enhancing both testing efficiency and their own skill development. Because all agent activities are processed through Burp Suite, testers are provided with reproducible evidence, including detailed requests and responses. This contrasts with relying solely on an AI's self-reported summary of its actions, ensuring a higher degree of transparency and auditability.

This initial release marks the first phase of PortSwigger's broader roadmap for Burp AT. Currently, the tool operates within a human-led workflow, augmenting the capabilities of individual testers rather than replacing their oversight. PortSwigger has indicated plans for future iterations that will introduce additional operating modes tailored for teams and enterprises. These may include more autonomous testing capabilities under predefined policies, featuring shared visibility and robust audit trails, while always maintaining human-led testing as a permanent option.

Speaking on the launch, PortSwigger Founder and CEO Dafydd Stuttard emphasized that trust in AI must be earned. He noted that while Burp Suite has established credibility over two decades of real-world use, Burp AT is a new offering that must prove itself through rigorous testing. This is why the company opted for a public beta release, encouraging security professionals to stress-test the tool and actively contribute to its ongoing development.

Burp AT is now accessible to all users of Burp Suite Professional, providing a practical entry point for security professionals seeking to integrate agentic AI into their existing penetration testing workflows without compromising control over sensitive engagements.

Synthesized by Vypr AI