Fran Hutchings | Monday, 27 July 2026 at 12:51 UTC

AI can already find and exploit vulnerabilities. The question is no longer whether the technology is capable. It is what kind of AI you can trust against systems you are responsible for testing.
Today, we are launching Burp AT in public beta for Burp Suite Professional users.
Burp AT lets you put agentic AI to work inside Burp Suite. Agents pursue the tasks you hand them using Burp’s specialist tools, the context gathered in your project, and pentesting skills developed with PortSwigger Research, all while you stay in the loop for scope, judgment, and conclusions.
That means you can hand agents investigations that would otherwise compete for your limited time and attention, while you focus your expertise where it matters most. Leads can be pursued further, unfamiliar areas explored more deeply, and worthwhile work that might otherwise go untouched can become part of the test.
Frontier AI models can find and exploit vulnerabilities. Agents can form a hypothesis, act through tools, interpret what they learn, and decide what to try next.
But a professional pentest requires more than capable reasoning. It requires reliable specialist tools, access to relevant context, purpose-built methodology, and boundaries the model cannot bypass.
Burp AT is built around all four:
The fastest way to see the value is to hand Burp AT a lead you would usually run out of time to chase. Something as simple as:
Analyze the minified JavaScript loaded by this target, reconstruct the endpoints and workflows it references, and flag anything that looks sensitive or unauthenticated and worth investigating further.
In our closed beta, one professional pentester did exactly that against 66,000 lines of minified JavaScript they could never have read by hand inside a four-day engagement. Burp AT helped surface a critical vulnerability that would otherwise have gone untested for at least another year.
This is life changing. I cannot begin to express how much easier it started making certain portions of the testing, and how much easier it has made learning. - Pentester, Closed Beta
Because the work runs through Burp, the resulting requests, responses, and evidence are tracked, so you can reproduce the finding and stand behind it rather than relying on a model’s account of what it did.
This is the first release of Burp AT, available today to Burp Suite Professional users. It brings agentic AI into a human-led pentesting workflow: agents take on more of the work inside Burp, while you retain control of scope, judgment, and conclusions.
Today, Burp AT works alongside you in the Burp workflow. Over time, the same foundation will support more operating modes for teams and enterprises, including more autonomous testing under standing policy, shared visibility, and auditability. Human-led testing remains one of those modes.
We will keep improving its tools, skills, and workflows as more people put it to work and share their feedback, and we will stay clear about what it can do today and where it is still developing.
Burp Suite has earned trust through more than two decades of use against real applications. Burp AT is new, and it has to earn that trust in the real world. That is why we are launching it as a public beta: so professional testers can put it to work, show us where it performs well and where it falls short, and help shape what it becomes. - Dafydd Stuttard, Founder and CEO, PortSwigger
The shape of pentesting is changing. Burp AT gives you a way to put agentic testing to work on your terms, built on the Burp Suite tools you already trust.
See everything Burp AT can do, and start using it in public beta today.