← All Quick Takes
Security12 March 2026

From quarterly pen tests to a persistent AI adversary

A diagram illustrating a continuous, sandboxed AI penetration tester that runs against your own attack surface and publishes its full reasoning to developers.

Here's what I've been thinking about. What if your security team stood up a dedicated environment with read only data permissions and gave an AI model the tools to actively scan and attempt to compromise your application? Not a one time audit. A persistent adversary that thinks differently than your red team does.

The environment is sandboxed. The data permissions are locked down so accidents stay contained. The model gets the same tooling your pen testers use: port scanning, fuzzing, payload generation. But it runs continuously, not on a quarterly schedule.

What separates this from a standard pen test report is capturing the chain of thought. The model's full reasoning gets published directly to your development teams: what was tried, what failed, what worked, and why the successful approach worked. Your developers learn how the vulnerability was found, not just that it exists.

Right now most security teams are dealing with the fallout of AI accelerating development. More code, faster releases, same size team reviewing it. Pointing that same capability at your own attack surface seems like a better response than trying to keep up manually.

How is your security organization preparing for this? And will the model providers allow it?

Duane Grey

Written by Duane Grey

AI Strategy & Implementation

Independent AI consultant helping companies cut through hype and deploy systems that produce real results.

Considering an AI initiative?

Let's name where it fits, then build it.

Start a Conversation