Plainsea has officially launched an autonomous agentic penetration testing capability within its platform, designed to continuously validate web-application exposure as environments change. The company is positioning the release as a response to a security reality many teams recognize: the moment a point-in-time test ends, the system begins drifting away from what was validated.

The agentic capability runs inside a persistent testing environment that retains scope, evidence, and historical context across cycles – an approach meant to reduce the “start-from-zero” friction that often comes with repeating assessments and to keep results comparable over time.

“Plainsea’s agent is built for the reality that your application changes constantly. The goal is to reduce the time you’re exposed between releases – without increasing headcount or turning every change into a new engagement.” said Marko Simeonov, CEO of Plainsea.

What Plainsea’s agentic capability does

The initial release focuses on web applications - the attack surface where the еxposure gap is most acute - combining attack-surface mapping with active validation aligned to common web risk categories including the OWASP Top 10. The system is designed to reason about system behavior, form hypotheses, and plan, execute, and validate tests end-to-end within defined rules of engagement.

Every finding Plainsea surfaces is backed by an executed attack path and complete evidence. There is no scanner noise, no theoretical risk assessment, and no unconfirmed flagging - only what is actually exploitable in the target environment.

Most importantly, it comes with a deterministic safety envelope that keeps human authority intact at every critical decision point. Teams can constrain or expand autonomy based on scope, maturity, and governance needs, with full traceability built in to support auditability and defensibility.

Why it matters

Security validation is under pressure from three directions at once: attackers moving faster, environments growing larger, and regulators expecting stronger proof. Industry figures underscore the pace problem – 28% of exploits are launched within 24 hours of disclosure – while the cybersecurity workforce gap sits at roughly 4.8 million unfilled roles, limiting how much hands-on validation organizations can sustain. Meanwhile, widely referenced breach-cost analysis places the average cost of a breach at $4.88 million, raising the stakes of getting prioritization wrong.

At the same time, enterprise external assets have expanded sharply – often growing three to five times in three years – creating an “exponential” attack surface that periodic testing struggles to keep current. Regulatory signals are also trending toward continuity: DORA, NIS2, and SEC cybersecurity disclosure requirements are pushing organizations to demonstrate security posture with more frequency and rigor than an annual report can realistically support.

Where the market is headed – and why the agentic penetration testing needs governance

The launch lands in a market crowded with products branded as “AI security,” where the difference between automation and autonomy is often blurred. In penetration testing specifically, most solutions cluster into one of three models: manual, episodic engagements; automation platforms that scale execution but rely on predefined logic; or autonomous systems that show stronger reasoning but are still commonly used per engagement rather than as continuous validation.

Plainsea is targeting the intersection it believes remains underserved: autonomous execution that operates at machine speed, continuity that reduces exploitable time at risk between changes, and governance that keeps outcomes explainable and defensible.

“AI hype is cheap; validation is not. We’ve crossed an inflection point where AI can reason – not just automate – which means multi-step attacks get easier. The defensive answer can’t be ‘more tooling’ and ‘more dashboards.’ It has to be reproducible proof, inside clear boundaries, with an audit trail you can defend,” commented Boris Goncharov, Chief Strategy Officer at Plainsea.

The company’s broader framing aligns with the growth of AI-specific security spending. Estimates for 2026 put worldwide spending on AI-specific security products and services at roughly $51B, with about $35B allocated specifically to software and platforms (excluding general services) – a signal that organizations are moving from experimentation toward operationalized security use cases.

What’s next

Plainsea plans to build from the web-application agent toward production readiness and broader coverage through 2026 and beyond. Next milestones include deeper context validation, cloud attack validation across AWS, Azure, and GCP, and a Continuous Threat and Exposure Management (CTEM) module, with a beta planned for the end of Q2 2026 followed by an official release later in the year. Longer-term plans include unified exposure validation across web, cloud, and internal network assessment, business-level risk quantification, and autonomous risk reduction through predictive risk modeling.

Plainsea Launches Autonomous Agentic Penetration Testing