PortSwigger has opened public beta access to Burp AT, a new agentic AI layer built directly into Burp Suite Professional, marking one of the most significant shifts in the platform’s 20-year history.
Announced July 27, 2026, by Fran Hutchings, Burp AT lets AI agents autonomously investigate, analyze, and surface vulnerabilities using Burp’s own tooling, while human testers retain final authority over scope, judgment, and conclusions.
The release lands at a moment when the cybersecurity industry is grappling with a blunt reality: AI models can already find and exploit vulnerabilities. The unresolved question, as PortSwigger frames it, isn’t capability; it’s trust.
Burp AT Public Beta
Burp AT isn’t a chatbot bolted onto Burp Suite. It’s an agentic system that can form hypotheses, act through Burp’s specialist tools, interpret results, and decide next steps, all within a live pentesting project. Four design pillars anchor the release:
- Native tooling and context: Agents use the same battle-tested Burp tools pentesters have relied on for two decades, pulling from existing project traffic, target structure, and prior findings rather than starting cold.
- Purpose-built skills library: Developed alongside PortSwigger Research, this gives agents structured methodologies instead of improvised, general-model reasoning.
- Configurable autonomy: Testers set exactly how much latitude agents get, per task, target, or risk level, ranging from full autonomy to mandatory approval gates.
- Architectural boundary enforcement: Scope and permissions live in Burp’s tooling layer, separate from the AI model itself. Agents can propose actions; only Burp can execute them, and every decision is logged.
The standout proof point from PortSwigger’s closed beta involves a pentester who tasked Burp AT with reverse-engineering 66,000 lines of minified JavaScript, work that was practically impossible to complete manually within a four-day engagement window.
The agent reconstructed endpoints and workflows, flagged unauthenticated exposure, and helped surface a critical vulnerability that otherwise would have gone untested for at least another year.
That case illustrates the core value proposition: Burp AT doesn’t replace tester judgment; it extends tester bandwidth into areas that time constraints would normally force testers to skip entirely.
What separates Burp AT from generic AI-assisted security tools isn’t the model; it’s the enforcement architecture. By keeping scope and approval logic outside the model’s control, PortSwigger is directly addressing a concern that’s dogged agentic AI security tools industry-wide: models that quietly exceed authorized boundaries during autonomous operation.
Every proposed action generates an auditable trail, giving testers reproducible evidence rather than a model’s unverified narrative of what happened.
CEO Dafydd Stuttard acknowledged this trust gap directly, noting that while Burp Suite has earned two decades of credibility, “Burp AT is new, and it has to earn that trust in the real world.” The public beta is explicitly framed as a mechanism to stress-test that trust with real practitioners before wider rollout.
This release represents phase one of a broader roadmap. PortSwigger has signaled future “operating modes” for enterprise teams, including more autonomous testing under standing policy, shared visibility across teams, and expanded auditability, while preserving human-led testing as a permanent option rather than a legacy fallback.
For an industry watching agentic AI reshape offensive security tooling in real time, Burp AT’s phased, permission-gated approach offers a notable contrast to fully autonomous pentesting platforms emerging elsewhere in the market.