Would you trust an AI to safely run PoC exploits against your production environment?

by

I've been building in the autonomous pentesting space, and this question keeps coming up in conversations with security folks, so I'm curious what this community actually thinks.

Traditional vulnerability scanners flag theoretical risk (version X might be vulnerable to CVE Y) but leave you to manually verify what's real. Manual pentests solve that by actually exploiting things, but only a human tester touches production, on a scoped schedule, with a lot of trust built in over time.

Now that AI agents can chain findings and execute proof-of-concept exploits autonomously, the obvious next question is: would you actually let one run against your live environment?

Curious where people land on this , is it a "never, full stop" for you? Does it depend on the guardrails (non-destructive PoCs only, no data modification, human approval gates)? Or does the idea of any autonomous system touching prod feel like a non-starter regardless of safety design?

Would love to hear real opinions here, especially from anyone who's had to make this call for their own team.

6 views

Add a comment

Replies

Be the first to comment