# What happened
# Why they built it
# How AI PT works AI PT uses purpose-built agentic AI to map a live attack surface across applications and APIs, build a threat model, craft exploits the way an attacker would, and run those exploits against live applications.
Discovery and authentication are performed by Bright's existing DAST engine rather than by AI guesswork. That same deterministic engine already supports Bright's Dynamic Testing and STAR Harness modules. Teams can choose black-box or gray-box engagement depth, and they can run the module fully autonomously or require human gating on exploit steps.
# Claimed benefits
- Continuous coverage: every release can be tested rather than relying on periodic scheduled tests.
- Validated results: exploits are proven against the live application, reducing false positives associated with some automated approaches.
- Cost and speed: Bright positions AI PT as significantly faster and cheaper than traditional third-party pentest firms and as more predictable and lower-cost than pure AI-only pentesting solutions.
- Integration: AI PT integrates into Bright's platform and management workflows.
# Availability and customers AI PT is stated to be available now as part of the Bright Security platform. The announcement says security teams at several global top-10 insurance and financial institutions already use Bright's platform.
Gadi Bashvitz, CEO of Bright Security, framed the launch as a response to advanced AI tools that can discover and weaponize software flaws quickly, saying manual pentesting wasn't built to run at the speed of AI-assisted development. Tom, VP Product at Bright Security, emphasized that AI Pentesting is built on Bright's discovery, authentication, and centralized management platform to reduce time to detect vulnerabilities while delivering predictable, lower-cost results.
# What to watch next
- How effectively AI PT reduces false positives in operational use compared with other automated pentesting claims.
- Whether organizations adopt continuous AI-driven pentesting in place of, or alongside, periodic manual engagements.
- The real-world remediation timelines after continuous AI PT findings versus traditional pentest reports.
# Bottom line Bright Security's AI PT combines agentic AI exploit generation with a deterministic DAST foundation to provide continuous, validated penetration testing integrated into its SDLC-focused platform. The claim is faster, lower-cost, and more frequent validated testing to address the narrowed window between disclosure and exploitation.