AI Threat Detection

Wiz Red Agent Now Generally Available for Continuous AI-Powered Penetration Testing

Wiz has announced the general availability of its Red Agent, an AI-powered attacker designed to continuously uncover complex, exploitable risks across applications and APIs. During preview, the Red Agent discovered more than 10,000 validated critical risks, with 70% of organizations finding high or critical vulnerabilities they were previously unaware of. The solution addresses the growing gap between traditional security scanning and the speed at which AI-enabled adversaries can exploit vulnerabilities.

Updated on July 29, 2026
Wiz Red Agent Now Generally Available for Continuous AI-Powered Penetration Testing

Wiz today announced that its Red Agent is now generally available. The AI-powered attacker is designed to help organizations continuously uncover complex, exploitable risks and stay ahead in what Wiz calls the AI Threat Era.

During its preview period, the Red Agent demonstrated clear impact: it discovered more than 10,000 validated critical exploitable risks that were externally facing and required no authentication. Seventy percent of organizations that enabled the agent found a high or critical vulnerability they were completely unaware of, and 35% discovered their first verified critical vulnerability within one hour of activating scans. At peak scale, the agent scanned 350,000 assets and processed 480 billion tokens in a single day.

The Red Agent addresses longstanding limitations of traditional security approaches. Static scanners often miss logic flaws, broken access controls, and multi-step vulnerabilities in modern applications and AI-generated code. Manual penetration testing is expensive, slow, and limited in scope, while point-in-time testing leaves new gaps the moment code or APIs change. In contrast, the Red Agent runs continuous, autonomous AI pentesting that reasons through business logic to identify unknown vulnerabilities such as OWASP API Top 10 issues, authorization bypasses, and other complex flaws.

Customer feedback during preview highlighted the practical value:

“The Red Agent for attack surface management and automated penetration testing is incredibly valuable. We didn’t have coverage over infrastructure-related automated pen testing prior to Wiz.”

— Patrick O’Boyle, Founding Security Engineer and Head of GRC, Rogo

“Red Agent finds what humans miss. It caught critical authorization flaws across services where traditional testing and our bug bounty program came up short.”

— Emil Vaagland, Head of Product Security, Vend

The general availability of the Red Agent marks a shift toward using AI for continuous defensive testing at a pace that can match AI-enabled adversaries.

Conditions Driving the Change

  • Attackers are increasingly using frontier AI models to scan perimeters, discover vulnerabilities, and weaponize complex application flaws in hours rather than months, creating a growing speed gap that human-paced security workflows cannot close.

  • Traditional static scanners rely on known CVEs and signature matching, which leaves them unable to reason about custom application workflows, broken access controls, multi-step logic flaws, or vulnerabilities in AI-generated code.

  • Manual penetration testing remains expensive, time-consuming, and limited in scope, making it impractical for continuous coverage across modern web applications, APIs, and rapidly changing environments.

  • Point-in-time testing and periodic audits create recurring security gaps the moment new code is shipped or APIs are updated, leaving organizations exposed between testing cycles.

  • Organizations need continuous, autonomous discovery of exploitable risks — including shadow APIs, authorization bypasses, and business-logic vulnerabilities — that traditional tools consistently miss.

  • The volume and complexity of externally facing attack surfaces continue to expand, requiring security teams to validate real-world exploitability rather than rely solely on theoretical vulnerability findings.

  • Early adopters of AI-powered offensive testing have already demonstrated that continuous autonomous agents can surface high and critical risks that existing scanners, bug bounty programs, and manual testing overlooked.

  • Security leaders are prioritizing AI Threat Readiness as a practical operating model, recognizing that defending against AI-speed adversaries requires deploying AI for continuous defensive testing at comparable scale and velocity.

What AI Security Testing Looked Like Before

Before continuous AI-powered offensive testing tools such as the Wiz Red Agent reached general availability, most organizations assessed their external attack surface through a combination of static vulnerability scanners, scheduled manual penetration tests, and occasional bug bounty programs. Static scanners performed well at identifying known CVEs and signature-based issues, but they were fundamentally limited when facing custom application workflows, multi-step business logic flaws, broken access controls, or vulnerabilities introduced by AI-generated code. They could flag theoretical weaknesses; they could not reliably reason about whether those weaknesses were actually exploitable in context.

Manual penetration testing filled some of that gap by bringing human expertise to complex authorization and logic issues. However, these engagements were expensive, required significant coordination, and typically spanned only a limited scope over a fixed window of days or weeks. Once the test concluded, the environment continued to change. New code deployments, API updates, and infrastructure modifications rapidly reopened exposure windows that remained unmonitored until the next scheduled assessment. Shadow or unlinked APIs frequently escaped detection entirely.

As a result, security teams often discovered critical, externally facing risks only after an attacker or an external researcher found them first. Continuous validation of real-world exploitability across a growing and dynamic attack surface was largely unavailable. Organizations were left relying on human-paced workflows and point-in-time snapshots while adversaries began accelerating their own discovery and exploitation cycles with frontier AI models. The coverage deficit between defensive testing capacity and offensive AI speed continued to widen.

What AI Security Testing Looks Like Now

With the general availability of the Wiz Red Agent, organizations can deploy continuous, autonomous AI penetration testing that reasons through application behavior rather than depending solely on known signatures or periodic human review. The agent is designed to uncover and validate complex, exploitable risks — including authorization bypasses, OWASP API Top 10 issues, multi-step logic flaws, and other high-impact vulnerabilities — across custom-built software, modern APIs, and evolving external attack surfaces.

During its preview period, the Red Agent demonstrated measurable impact at scale. It discovered more than 10,000 validated critical exploitable risks that were externally facing and required no authentication. Seventy percent of organizations that enabled the agent found a high or critical vulnerability they were previously unaware of, and 35 percent identified their first verified critical finding within the first hour of scanning. At peak, the system processed hundreds of thousands of assets and hundreds of billions of tokens in a single day, showing that continuous AI-driven testing can operate at a volume and velocity traditional approaches cannot match.

The agent combines intelligent discovery capabilities, such as mapping shadow and unlinked APIs through client-side analysis, with an attacker component that actively validates whether identified weaknesses are exploitable. This shifts the security model from periodic, limited-scope assessments to ongoing validation that reduces the window of exposure created by continuous development and deployment. Early customers report that the Red Agent surfaces issues missed by conventional scanners, internal testing, and even bug bounty programs, giving security teams earlier and more actionable insight into risks that matter most.

The result is a practical step toward AI Threat Readiness: using AI defensively at a pace that can more closely match the speed of AI-enabled adversaries.

Our Take

AI Security Take

The general availability of the Wiz Red Agent marks a meaningful shift in how organizations can approach continuous security testing in the AI Threat Era. As adversaries increasingly use frontier models to discover and weaponize vulnerabilities at machine speed, relying on static scanners and periodic manual penetration tests leaves a growing coverage gap. The Red Agent addresses that gap by bringing continuous, autonomous AI-powered offensive testing into production security workflows.

The core value is the ability to reason about complex, exploitable risks rather than simply matching known signatures. Traditional tools miss many logic flaws, authorization bypasses, and multi-step vulnerabilities in modern applications and APIs. Manual testing can find them but cannot scale or keep pace with continuous development. By combining intelligent discovery (including shadow API mapping) with active validation of real-world exploitability, the Red Agent reduces the window between when a risk appears and when it is identified.

Preview results reinforce the practical impact: more than 10,000 validated critical risks discovered, a majority of organizations finding high or critical issues they did not previously know existed, and rapid time-to-first-critical findings. These outcomes suggest that continuous AI attackers can surface risks that existing scanners, internal testing, and even bug bounty programs overlook.

For security leaders, the implication is clear. Defending against AI-accelerated adversaries requires deploying AI for continuous defensive testing at comparable scale and velocity. Organizations that continue to rely primarily on point-in-time assessments and signature-based tools will face an expanding exposure window. Those that adopt continuous AI-powered validation will be better positioned to identify and prioritize the risks that matter most before attackers do.

The Red Agent’s general availability is one of the clearer signals yet that AI Threat Readiness is moving from concept to operational capability. Continuous autonomous testing is becoming a practical requirement for keeping pace with both modern development velocity and AI-enabled offensive capabilities.

Related Articles

ServiceNow Launches Autonomous Workforce and Integrates Moveworks Into Its AI Platform AI Governance Platforms

Feb 27, 2026

ServiceNow Launches Autonomous Workforce and Integrates Moveworks Into Its AI Platform

Read More
Arize vs Fiddler vs Arthur: Which AI Monitoring Platform Actually Fits Your Enterprise? Model Observability

Mar 1, 2026

Arize vs Fiddler vs Arthur: Which AI Monitoring Platform Actually Fits Your Enterprise?

Read More
ServiceNow Introduces the Enterprise Identity Control Plane Following Its Acquisition of Veza AI Access Control

Mar 2, 2026

ServiceNow Introduces the Enterprise Identity Control Plane Following Its Acquisition of Veza

Read More

Stay ahead of Industry Trends with our Newsletter

Get expert insights, regulatory updates, and best practices delivered to your inbox