PortSwigger introduces Burp AT in public beta, integrating AI capabilities into its widely used Burp Suite Professional platform This article explores autonomous testing established. . The release represents a pivotal shift in how penetration testers approach web application security assessments, combining autonomous AI agents with over two decades of proven Burp Suite tooling.

Agents leverage Burp's battle-tested toolkit and draw upon existing project context, including traffic, target structure, and prior discoveries, working alongside testers rather than starting from scratch. Testers retain full control over autonomy, deciding what proceeds automatically, what requires approval, and what remains blocked, adjusting this balance by task, target, and risk level.

Frontier AI models can already generate hypotheses, execute exploits, and interpret results; the real challenge lies in ensuring that autonomy operates within verifiable, auditable constraints during professional engagements. PortSwigger refers to this as the initial phase of a broader rollout, aiming to introduce additional autonomy modes for enterprise teams, including more autonomous testing under established policies with shared visibility and auditability, while maintaining human-led testing as a permanent operational mode. Founder and CEO Dafydd Stuttard highlighted that the public beta phase is intended to validate Burp Suite’s reliability through real-world testing, emphasizing that despite its newness, Burp AT still needs to earn trust in the field over two decades of real application testing experience.