Service
Artificial intelligence penetration testing for products built on LLMs
Artificial intelligence penetration testing checks how a product that uses a language model behaves under hostile input. So it covers the model's surroundings, not just the web app around it.
- Named tester before day one
- One retest within 30 days
- OWASP WSTG and NIST SP 800-115
What artificial intelligence penetration testing covers
Products now wrap language models in tools, data sources and agents. Therefore new risks appear where the model can read data or trigger actions on a user's behalf.
A test looks at those boundaries. For example, whether the model can be steered into revealing data it should not, or into calling a tool it should not use.
- Prompt handling and instruction boundaries
- Access to connected data sources
- Tool and plugin permissions
- Output handling in the surrounding application
- Logging and abuse monitoring
Scoping artificial intelligence penetration testing
Scope starts with what the model can touch. Also, it covers who can talk to it, because public chat and internal assistants carry different risks.
| Scope question | Why it matters |
|---|---|
| Which data sources can the model read? | Leakage risk depends on them |
| Which actions can it trigger? | Agents raise the stakes |
| Who can reach it? | Public access widens exposure |
| Which provider hosts the model? | Their terms set testing limits |
Artificial intelligence penetration testing readiness check
Tick what you can already describe. Open items become scope questions.
Your result appears here as you tick, so you can see what is still open.
Authorisation and provider terms
Testing needs your written authorisation, as always. However, third-party model providers also publish usage policies. So the rules of engagement respect those terms, and testing targets your application rather than the provider's platform.
In addition, test accounts and rate limits are agreed in advance. As a result, testing does not disturb real users.
What the artificial intelligence penetration testing report shows
Findings come with evidence, impact and a fix. Also, they map to recognised guidance where it helps your engineers. For example, the OWASP Top 10 for LLM Applications gives a shared vocabulary.
The report is written for auditors and customers as well. So an attestation letter can be shared without exposing details.
Fees and timing
AI work is priced after scoping, because surfaces vary widely. Most companies land between $10,000 and $30,000, and the exact figure follows scope. One retest within 30 days is included, and a named tester is confirmed before day one. Methodology follows the OWASP Web Security Testing Guide and NIST SP 800-115, extended for model behaviour.
Artificial intelligence penetration testing questions
Is artificial intelligence penetration testing different from web testing?
Partly. The web layer is tested as usual, while model behaviour and tool access add new checks.
Do we need the model provider's permission for artificial intelligence penetration testing?
You authorise testing of your application. Provider terms still apply, so the rules of engagement respect them.
Can artificial intelligence penetration testing find every model weakness?
No. It shows what an attacker could do within scope and time, with evidence.
Is a retest included?
Yes. One retest within 30 days is included.
Related guides
Scope your artificial intelligence penetration testing
Tell us what the model can read and do. We reply with a written estimate, usually within four working hours, and testing starts only after you sign the authorisation.
Get my estimate