IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
PortSwigger launches Burp AT public beta for pentesters

PortSwigger launches Burp AT public beta for pentesters

Thu, 30th Jul 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

PortSwigger has launched the public beta of Burp AT for professional pentesting in Burp Suite, adding agentic AI to its web security testing platform.

Burp AT is aimed at security professionals who want to use AI agents for investigative testing tasks inside Burp Suite while retaining control over what those agents can do. Pentesters can decide how much work to delegate, with scope, permissions, and approval rules enforced by Burp rather than left to the model.

The launch marks PortSwigger's move to bring agent-based AI into a product already widely used by web application testers. Burp Suite is used by more than 90,000 security professionals and 18,000 organisations across more than 170 countries.

Burp AT allows agents to pursue defined tasks using Burp Suite's existing tools, project context, and what PortSwigger describes as purpose-built pentesting skills. Agents can draw on information already held in a Burp project, including traffic, target structure, issues, and discoveries gathered during an engagement.

That shared context is intended to let later investigations build on earlier work rather than start from a blank prompt. Agents can also add their own findings to the project record as testing progresses.

Control model

A central part of the product is the way human testers retain oversight. Users can allow actions to proceed automatically, require approval before they continue, or block them altogether.

PortSwigger says smart approvals are designed to let routine work continue while escalating decisions that need a tester's attention. Users can begin with tighter supervision and increase autonomy when the target, engagement rules, and the agent's performance make that appropriate.

These controls are enforced in Burp's tooling layer rather than through prompts or instructions given to the model. In practice, that means an agent can suggest an action but cannot carry it out if Burp does not permit it.

Agent requests and tool activity are also recorded in the Burp project. This gives testers a log they can inspect alongside other engagement evidence rather than relying only on the model's own account of what happened.

Built on Burp

PortSwigger is positioning the product as an alternative to ad hoc workflows built around general AI coding agents, scripts, and integrations. Rather than relying on general-purpose HTTP libraries, Burp AT works through Burp Suite's web security testing tools.

According to PortSwigger, those tools reflect more than two decades of use against real applications and can handle malformed requests, message manipulation, and protocol edge cases that often arise in professional testing. The aim is to let the model focus on deciding what to investigate and what to try next.

Burp AT also includes structured, task-specific pentesting skills developed with PortSwigger Research. These skills are intended to give agents repeatable testing approaches without requiring every user to build a methodology through prompts, scripts, or workflow instructions.

PortSwigger says the skills create a path from security research into applied testing. As new techniques are developed and validated by its research team, they can be translated into skills that agents use during engagements.

Trust question

Dafydd Stuttard, Burp Suite Creator and Chief Executive Officer of PortSwigger, framed the launch around the gap between AI demonstrations and production use on live targets.

"AI can already find vulnerabilities. The harder question is whether you can trust it against a real target. Burp AT gives the model room to reason, but Burp controls what it can actually do, executes the work through tools pentesters already rely on, and preserves the evidence. That is what turns agentic testing from an impressive demonstration into something useful on a real engagement," said Stuttard.

The public beta is available to Burp Suite Professional users. PortSwigger plans to expand the product during the beta and use feedback from real engagements to shape its tools, skills, and workflows.

The company's wider product portfolio spans practitioner-led testing and application security tools for larger organisations. Burp Suite DAST is used by more than 1,000 organisations to automate application security testing, while PortSwigger's software and research are also used in strategic work with large enterprises including SAP.