Whitepaper / August 2026
Human-led offensive security in the age of AI.
Practical governance for using AI across offensive security without weakening human judgement, operational control or evidence quality.
14-page PDF. No registration required.
- Published
- 12 August 2026
- Length
- 14 pages
- Audience
- Boards and executives
- Focus
- Australian organisations
// Inside the paper
Use AI for leverage without delegating accountability.
AI can help consultants analyse more material, explore hypotheses and produce repeatable test artefacts. Its output remains untrusted working material until a qualified person validates it against the target and preserves reproducible evidence.
Where AI can assist
Scoping, attack-surface analysis, code review, test development, evidence analysis, reporting and regression testing.
Why human judgement remains essential
Authority, business context, adaptive attack paths, exploitability, safety and accountable communication.
How to control AI-assisted testing
Four modes of use, an engagement lifecycle, explicit approval boundaries and an evidence standard.
What leaders and buyers should ask
Questions covering data handling, model providers, executable authority, validation, containment and professional accountability.
// Leadership decisions
Five decisions for responsible AI-assisted delivery.
The framework treats AI as part of the offensive-security toolchain. Authority, safety decisions, finding validation and final reporting remain human responsibilities.
Keep a qualified human accountable.
A named consultant owns scope, safety decisions, finding validation, impact assessment and the final report.
Extend coverage, not lower the evidence standard.
Every reported finding still needs a reproducible path, demonstrated effect, impact statement and human sign-off.
Protect client information by design.
Approve models, data classes, retention, processing regions and technical access controls before sensitive material is used.
Separate assistance from authority.
Reading and proposing are lower risk than sending traffic, using credentials, changing state or communicating externally.
Tell clients how AI materially affects delivery.
Contracts and reports should identify material AI use, data handling, human validation and relevant limitations.
// Evidence standard
Measured claims, stated limitations.
- 17 cited sources, prioritising government guidance, recognised standards and primary disclosures.
- The same evidence standard applies whether a finding began with human analysis, established tooling or AI assistance.
- AI-generated text, code and screenshots are not proof by themselves.
- Target-derived evidence and accountable human review remain decisive.
Download the full framework.
Read the complete 14-page paper, including the operating premise, workflow matrix, risk controls, engagement lifecycle and leadership questions.