PortSwigger has launched a public beta of Burp AT, introducing agentic AI capabilities to its widely-used Burp Suite penetration testing platform. The new tool represents a significant addition to professional security testing workflows by enabling AI agents to perform defined investigative tasks autonomously.
Burp AT operates within the existing Burp Suite framework, allowing penetration testers to delegate specific security testing tasks to AI agents. These agents leverage Burp Suite's established toolset, project context, and specialized penetration testing capabilities to conduct investigations. The system is designed to augment rather than replace human expertise in security assessments.
The tool includes built-in controls that maintain human oversight throughout the testing process. Burp Suite enforces scope limitations, permission boundaries, and approval workflows to prevent AI agents from operating outside defined parameters. Testers can adjust how much work the agents perform, maintaining granular control over automated activities. The system requires human validation of findings and preserves the tester's responsibility for exercising professional judgment.
This release addresses a growing interest in AI-assisted security testing while acknowledging the continued need for human expertise. By automating routine investigative tasks, Burp AT aims to free penetration testers to focus on complex analysis and decision-making that requires human judgment. The agentic approach differs from simple automation by allowing AI to make contextual decisions within predefined boundaries.
Security professionals interested in testing Burp AT can access the public beta through PortSwigger's platform. Organizations should evaluate how the tool fits within their existing security testing processes and consider appropriate governance frameworks for AI-assisted penetration testing. As with any beta software, users should monitor performance and provide feedback to help refine the tool's capabilities before general release.
Source: https://www.helpnetsecurity.com/2026/07/30/portswigger-burp-at/


