PortSwigger Launches Burp AT Public Beta for Human-Led Pentesting
PortSwigger launched Burp AT in public beta on July 27 for Burp Suite Professional users, adding agents that can pursue testing goals with Burp's tools and project context. Testers set scope and approval levels while Burp's tooling layer enforces boundaries and logs activity, making the release an assisted pentesting workflow rather than an autonomous replacement for human judgment.
PortSwigger launched Burp AT in public beta on July 27, 2026, for Burp Suite Professional users. The feature puts AI agents inside the existing Burp workflow so they can pursue testing goals with Burp's tools, the target context already captured in a project, and specialized methods developed with PortSwigger Research.
What the public beta does
Burp AT organizes work into tasks that testers assign. Agents can inspect project context, choose actions, use Burp's web-security tools and record resulting requests, responses and findings in the same project. PortSwigger says users can set different autonomy levels, from manual approvals to broader routine action, while some high-impact operations still require review.
The most consequential design choice is where those limits live. PortSwigger says scope, tool access and approval rules are enforced by Burp's tooling layer rather than left to model instructions. That separation is intended to prevent an agent from acting outside the permissions a tester configured and to leave a reproducible activity trail.
Evidence and limits
PortSwigger's July 27 announcement calls this the first phase of Burp AT and explicitly keeps scope, judgment and conclusions with the human tester. The company cited a closed-beta example in which the system analyzed 66,000 lines of minified JavaScript during a four-day engagement and helped surface a critical vulnerability. That is a vendor-reported case, not independent evidence of general performance.
Independent coverage confirms the public-beta launch and the same control model, but the release does not establish how reliably Burp AT finds vulnerabilities across targets, how often it produces false leads, or how its cost compares with manual work. Teams evaluating it should therefore treat the beta as a supervised testing tool and validate findings through the recorded traffic and evidence.
Why it matters
For security teams, the practical change is that agentic investigation now runs inside a widely used professional testing environment instead of through a separate coding-agent stack. That can make delegated work easier to audit, but it does not remove the need for target authorization, careful scope controls, reproducibility and human review of impact. The public beta is available to Burp Suite Professional users.
Key Points
- 1Burp AT is live in public beta for Burp Suite Professional users after PortSwigger announced the launch on July 27, 2026.
- 2Agents use Burp tools and project context, while scope and approval boundaries are enforced outside the model in Burp's tooling layer.
- 3The launch is a human-led workflow; PortSwigger has not published broad independent performance evidence for the beta.
Scoring Rationale
A major security-testing vendor has embedded agentic investigation into its professional workflow with explicit external permission controls; practical impact is meaningful, but general performance remains unproven in public beta.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems