Risky Business · Wednesday, August 5, 2026
Adam drew a parallel between the behavior of AI agents like OpenAI's and junior penetration testers. He noted that while both are technically proficient and eager, they struggle with understanding and adhering to scope. He suggested that training AI agents to consider business context and limitations is a significant challenge, akin to guiding human testers.
“But then yes, it really does remind me of, you know, hiring junior pent testers that are amazing technically and are super keen to prove themselves, and will, you know, dog with a bone down whatever rabbit hole you point them in, but then making them stop and make them think about scope, that's hard.”
“So, I mean, we could turn, not with 100% success, like we could turn junior pent testers into, you know, usable consultants, uh, with enough, you know, combination of carrot and stick, but, uh, that's the problem they've got here is that hacking is lots of fun and the model is really good at that. But scope and business, and, you know, doing what you're told, uh, a little more involved.”
“But, you know, we do it with humans. So presumably we can do it with LLMs, eventually, I hope, maybe?”