Opens in a new tab
vmblog logo 2024 wht (updated)

BreachLock’s New AI Agent Wants to Hack Your Network — With Your Permission First

Share: 

David Marshall | Published: August 27, 2026
breachlock new ai agent

There’s a particular flavor of anxiety that comes with running a security team in 2026. Vulnerability scanners keep piling up alerts. Half of them turn out to be noise. And somewhere in that pile is the one flaw an actual attacker would use to walk right through the front door. Sorting the real threats from the theoretical ones has become its own full-time job, and most organizations don’t have the headcount for it.

BreachLock thinks it has an answer, and this week the offensive security company put it on the table. The company introduced Breach360, an agentic AI-powered autonomous penetration testing solution that folds directly into its existing platform alongside Attack Surface Management (ASM) and Penetration Testing as a Service (PTaaS). The pitch is straightforward enough: stop generating more lists of theoretical weaknesses, and start proving which ones an attacker could actually use.

What Breach360 Actually Does

Here’s the thing about most vulnerability management tools — they’re really good at finding problems and not so good at telling you which ones matter. Breach360 is built to close that gap by running autonomous tests against real attack paths and documenting, with evidence, whether something is truly exploitable.

According to BreachLock, Breach360 draws on intelligence pulled from more than 40,000 real-world penetration testing engagements, a dataset the company says informs how its AI agents reason through an environment. Rather than treating web application testing and network testing as separate disciplines with separate tools, Breach360 handles both from a single workflow — internal and external attack surfaces alike.

That consolidation is arguably the bigger story here. BreachLock is now positioning itself as the only offensive security vendor bundling continuous ASM, certified human-led pentesting, and autonomous pentesting into one platform. Whether competitors would quibble with “only” is a fair question (more on that below), but the underlying complaint Breach360 is responding to — tool sprawl — is one nearly every CISO has voiced at some point.

The Human-in-the-Loop Argument

Autonomous anything tends to make security leaders nervous, and for good reason. Handing an AI agent the ability to attempt lateral movement or exploit a live production system sounds like exactly the kind of thing that goes wrong in a postmortem slide deck. BreachLock says it heard that concern loud and clear.

“In the more than fifty CISO conversations that shaped Breach360’s vision, one thing became clear: the industry is ready to embrace autonomous pen testing, but not at the expense of control,” said Seemant Sehgal, Founder and CEO of BreachLock. “Human-in-the-loop kept coming up as a non-negotiable. The other consistent theme was fatigue with vendor sprawl. CISOs want consolidation across their attack surface, spanning both network and web. Breach360 is our answer to that.”

That framing shows up throughout the product itself, not just the marketing copy. Breach360 includes scope controls, approval gates for exploitation and lateral movement, guardrails, and what BreachLock describes as kill-switch capabilities — essentially an emergency brake a security team can pull mid-engagement. Organizations define what’s in bounds before the AI ever starts probing, and they can halt things if the agent starts wandering somewhere they didn’t intend.

There’s a bit of a contradiction worth sitting with here: the whole appeal of “autonomous” testing is that it moves faster and needs less hand-holding than a human red team. But BreachLock is explicitly building in checkpoints that slow the AI down at the moments that matter most. That’s not really a flaw in the pitch — it’s the point. Speed everywhere except the risky parts turns out to be a reasonable way to sell autonomy to a skeptical buyer.

What’s Under the Hood

BreachLock lists a handful of capabilities it’s leaning on to differentiate Breach360 from a glorified vulnerability scanner wearing an AI costume. A few worth flagging:

  • Proof of exploitability — findings come with documented evidence rather than a severity score pulled from a generic database.
  • Unified web and network coverage — one engagement, one report, instead of stitching together outputs from separate application and infrastructure tools.
  • MITRE ATT&CK alignment — testing logic is tied to documented attacker techniques rather than a static rule set.
  • Real-time attack path visibility — teams can watch how individual weaknesses chain together into something that actually matters to the business.

For teams that want an extra layer of assurance, BreachLock is also offering an optional human-verified results step, where a certified BreachLock pentester reviews the AI’s findings before they land in a final report. It’s a reasonable hedge — you get the speed of automation with a human still signing off on the homework.

Why This Is Happening Now

Breach360 doesn’t exist in a vacuum. Agentic AI has been creeping into every corner of security operations over the past year or so, and offensive security is one of the more logical places for it to land. Invicti Security launched its own Agentic Pentest product this past summer, pairing autonomous reasoning with its established DAST engine. Industry researchers tracking this space have pegged the broader agentic AI security market at roughly $1.65 billion in 2026, with some projections putting it above $13 billion by the early 2030s — a growth curve steep enough that pretty much every vendor with a pentesting product is going to feel pressure to ship something with “agentic” in the name.

What’s notable, though, is that human-in-the-loop isn’t just a BreachLock talking point. Market analysts have found that semi-autonomous, human-supervised systems are expected to make up the clear majority of agentic AI security deployments this year — a sign that “fully autonomous” is more of a long-term aspiration than something buyers are actually asking for right now. Security teams, it turns out, want the AI to do the grunt work. They just don’t want it making unilateral calls about exploiting production systems while nobody’s watching.

The Bigger Picture for CISOs

None of this eliminates the fundamental tension in security testing: speed versus assurance. Point-in-time pentests, run once or twice a year, have never matched the pace at which environments actually change — new cloud assets spin up, code ships, configurations drift. Continuous, AI-driven validation is the obvious answer on paper. The question every security leader has to answer for themselves is how much comfort they need before they let an autonomous agent loose on systems that keep the business running.

BreachLock’s bet is that the answer isn’t “none” or “total” — it’s somewhere in the middle, with guardrails doing the heavy lifting. Whether that’s enough to win over security teams still burned by past automation promises remains to be seen. But given how loudly the “vendor sprawl” complaint keeps surfacing in industry conversations, a platform that consolidates discovery, validation, and remediation guidance into one place is at least solving a problem people are actually willing to talk about out loud.

Breach360 is available now through the BreachLock Unified Platform. Organizations curious about how it handles their own environment can request a demo directly through BreachLock’s website.

##