Agentic AI may help security teams identify which weaknesses attackers could actually exploit—but autonomous offensive testing requires evidence, boundaries, and human oversight.
Security teams seldom suffer from a shortage of findings. The more constant problem is determining which findings describe a genuine path to compromise—and which will consume remediation time without materially reducing risk.
As AI speeds up software development and gives attackers new ways to accelerate their work, simply scanning for security flaws is no longer enough. Defenders need tools that can analyze how those flaws work together, determine whether an attack is truly possible, and provide reliable evidence that security teams can trust.
One potentially promising response to this challenge is RidgeGen, an agentic AI platform for continuous offensive security testing from Ridge Security. Announced on August 4, the platform is designed to reason through business logic, vulnerabilities, misconfigurations, credentials, and other contextual information to discover attack paths that conventional scanners may overlook.
The announcement reflects a larger shift in security testing: away from simply finding weaknesses and toward proving which combinations of weaknesses create exploitable risk.
It also raises a second, equally important question. If an AI system is going to behave like an attacker, how much freedom should an enterprise give it?
A vulnerability backlog is not a measure of risk
Vulnerability management has historically relied on identifying known weaknesses, assigning severity scores, and directing remediation teams toward the most urgent findings.
That process remains relevant, but it can produce a distorted picture of exposure.
A critical vulnerability may be inaccessible, mitigated by other controls, or located on a system with little business significance. Conversely, several weaknesses individually rated as moderate or low may give an attacker a viable route to sensitive information or privileged access when chained together.
Attackers do not necessarily approach an environment by working through its vulnerability list from the top down. They look for a path.
That path might begin with a configuration error, pass through an overlooked credential, exploit an application’s business logic, and eventually reach a high-value system. No single step has to appear catastrophic when viewed in isolation.
This is where RidgeGen’s approach becomes interesting. Rather than limiting its analysis to signatures, known Common Vulnerabilities and Exposures, or a predetermined testing catalog, the platform is designed to investigate how multiple conditions could be combined to compromise an environment.
Ridge Security describes that process as autonomous reasoning. The platform uses AI models, along with the company’s security knowledge base and specialized offensive security tools, to examine potential attack paths and determine whether they can be reproduced.
The goal is not simply to generate more findings. It is to identify which findings matter.
Treating security testing as an investigation
Traditional scanners are good at answering a specific question: Does this system appear to contain a known weakness?
An agentic testing platform attempts to answer a broader question: Given what is known about this environment, what could an attacker accomplish?
Answering that requires more than matching system characteristics against a vulnerability database. The platform must consider context, form hypotheses, select testing actions, evaluate the results, and adjust its approach as new information emerges.
RidgeGen is designed to perform that investigation continuously. Ridge Security says it can discover complex, multi-step attack chains as well as business-logic vulnerabilities that may not correspond neatly to a known CVE.
That could make the platform particularly relevant in environments where applications and infrastructure change frequently. A penetration test offers a valuable assessment of an organization at a particular moment. Still, new code, cloud resources, permissions, and integrations can alter the attack surface soon after the engagement concludes.
Continuous testing is intended to narrow that gap.
It should not, however, be viewed as a wholesale replacement for human penetration testers or red teams. Experienced practitioners bring intuition, creativity, organizational awareness, and an understanding of human behavior that an automated platform may not replicate.
The more likely model is one in which autonomous systems provide persistence, repeatability, and scale, while people determine testing objectives, interpret business consequences, explore novel scenarios, and make risk decisions.
Evidence matters more when AI makes the claim
Security professionals are already familiar with false positives from conventional tools. Introducing generative AI creates an additional concern: a system may produce a plausible explanation that is not adequately supported by what actually happened.
That is an inconvenient characteristic for many business applications. In offensive security, it can be dangerous.
An unverified finding could send an engineering team toward the wrong problem, create unnecessary concern about a critical system, or encourage someone to attempt remediation without understanding the real attack path.
Ridge Security says RidgeGen addresses this problem by validating findings with reproducible evidence before presenting them to the user. The company describes the platform as combining AI reasoning with deterministic verification, allowing the AI to investigate possibilities without giving its conclusions the status of fact until they have been demonstrated.
That separation is fundamental to the platform’s value proposition.
The company says this evidence-backed process eliminates false positives and AI hallucinations while dramatically reducing false negatives. Those claims will ultimately need to be judged through real-world deployments and independent evaluation. Nevertheless, the underlying principle is sound: the less predictable the reasoning system, the more important verifiable evidence becomes.
Security teams should be able to see what was tested, which steps succeeded, how the weaknesses were combined, and why the resulting attack path matters. A conclusion without that supporting trail would amount to another alert—albeit one written more persuasively.
Autonomy should not mean unrestricted authority
Validating attack paths requires a platform to do more than passively analyze information. It may need to interact with systems, use credentials, test controls, or attempt actions that resemble those of a real attacker.
That makes governance more than an administrative feature. It becomes part of the security architecture.
Ridge Security says RidgeGen separates AI reasoning from authority, enforcement, and verification. In practical terms, the AI may determine what it wants to investigate, but policies and runtime controls govern what it is permitted to do.
The platform includes supervised and authorized testing modes intended to restrict targets and permissible actions. Its SafeBox capability isolates credentials so that sensitive information does not enter AI model prompts or memory.
RidgeGen is also model-agnostic, according to the company, and can work with commercial or self-hosted AI models. On-premises deployment options are available for organizations that need to keep customer data, credentials, and testing evidence within their own environments.
These controls address some of the most immediate concerns surrounding autonomous offensive security, but enterprises will still need clearly defined operating procedures.
Before deploying such a system, an organization should understand which assets are in scope, what testing techniques are allowed, when human approval is required, how activity is logged, and how testing can be stopped. It should also establish who is responsible when an autonomous action produces an unexpected operational impact.
An AI agent should not receive broader authority simply because it can operate faster than a person.
Giving defenders an attacker’s perspective
“AI has fundamentally changed offensive security,” Lydia Zhang, president of Ridge Security, said in the announcement. “Attackers are already leveraging it to move faster, scale their operations, and uncover weaknesses more effectively.”
RidgeGen is intended to give defenders a comparable ability to explore their environments from an attacker’s perspective.
That does not necessarily mean fully autonomous cyberattacks have become the norm. It does mean AI can reduce the time and expertise required for portions of vulnerability research, reconnaissance, tool development, and attack planning.
Defenders must therefore consider how to use the same technological advantages without sacrificing control.
Jason English, director and principal analyst at Intellyx, sees continuous agentic testing as a way to give security teams “more context, less noise, and better visibility of the most significant risks.”
Context may prove to be the most consequential part of that equation. Most organizations already know they have vulnerabilities. What they need is a clearer understanding of which vulnerabilities create meaningful exposure and what should be done first.
Moving from “find” to “find, prove, and fix”
RidgeGen complements RidgeBot, Ridge Security’s continuous security validation platform. The company positions the two products as a unified “find, prove, and fix” approach to Continuous Threat Exposure Management, or CTEM.
In that model, broad visibility across the attack surface is paired with deeper autonomous testing of high-value targets. Once a potential attack path has been validated, RidgeGen can provide remediation guidance based on the evidence it collected.
This progression—from discovery to validation to remediation—is more useful than treating vulnerability identification as the end of the process.
The success of the approach will not be measured by how many findings the AI produces. It will depend on whether RidgeGen consistently discovers meaningful attack paths, supports its conclusions with trustworthy evidence, operates within carefully enforced boundaries, and helps security teams resolve genuine risk more quickly.
Those are demanding expectations. They are also the right ones.
As agentic AI moves into offensive security, speed alone will not be enough. Enterprises will need systems that can investigate like an attacker, prove what they find, and remain firmly under the defender’s control.
Additional Resources
Video Overview
Infographic

Steven Bowcut is the Editor-in-Chief of Brilliance Security Magazine and host of the BSM Podcast. He has spent years covering cybersecurity and physical security, focusing on the technologies, strategies, and leadership insights that matter most to security practitioners and decision-makers. Through the magazine and podcast, Steven brings readers and listeners practical content with industry leaders, innovators, and experts shaping the future of security. Follow and connect with Steve on Instagram and LinkedIn.

