Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Artificial intelligence penetration testing for products built on LLMs

Artificial intelligence penetration testing checks how a product that uses a language model behaves under hostile input. So it covers the model's surroundings, not just the web app around it.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Artificial intelligence penetration testing: define the ai scope, test with authorisation and report and retest

What artificial intelligence penetration testing covers

Products now wrap language models in tools, data sources and agents. Therefore new risks appear where the model can read data or trigger actions on a user's behalf.

A test looks at those boundaries. For example, whether the model can be steered into revealing data it should not, or into calling a tool it should not use.

  • Prompt handling and instruction boundaries
  • Access to connected data sources
  • Tool and plugin permissions
  • Output handling in the surrounding application
  • Logging and abuse monitoring

Scoping artificial intelligence penetration testing

Scope starts with what the model can touch. Also, it covers who can talk to it, because public chat and internal assistants carry different risks.

Scope questionWhy it matters
Which data sources can the model read?Leakage risk depends on them
Which actions can it trigger?Agents raise the stakes
Who can reach it?Public access widens exposure
Which provider hosts the model?Their terms set testing limits

Artificial intelligence penetration testing readiness check

Tick what you can already describe. Open items become scope questions.

Your result appears here as you tick, so you can see what is still open.

Authorisation and provider terms

Testing needs your written authorisation, as always. However, third-party model providers also publish usage policies. So the rules of engagement respect those terms, and testing targets your application rather than the provider's platform.

In addition, test accounts and rate limits are agreed in advance. As a result, testing does not disturb real users.

What the artificial intelligence penetration testing report shows

Findings come with evidence, impact and a fix. Also, they map to recognised guidance where it helps your engineers. For example, the OWASP Top 10 for LLM Applications gives a shared vocabulary.

The report is written for auditors and customers as well. So an attestation letter can be shared without exposing details.

Fees and timing

AI work is priced after scoping, because surfaces vary widely. Most companies land between $10,000 and $30,000, and the exact figure follows scope. One retest within 30 days is included, and a named tester is confirmed before day one. Methodology follows the OWASP Web Security Testing Guide and NIST SP 800-115, extended for model behaviour.

Artificial intelligence penetration testing questions

Is artificial intelligence penetration testing different from web testing?

Partly. The web layer is tested as usual, while model behaviour and tool access add new checks.

Do we need the model provider's permission for artificial intelligence penetration testing?

You authorise testing of your application. Provider terms still apply, so the rules of engagement respect them.

Can artificial intelligence penetration testing find every model weakness?

No. It shows what an attacker could do within scope and time, with evidence.

Is a retest included?

Yes. One retest within 30 days is included.

Related guides

Scope your artificial intelligence penetration testing

Tell us what the model can read and do. We reply with a written estimate, usually within four working hours, and testing starts only after you sign the authorisation.

Get my estimate