Penetration Testing for Agentic Processes:
Evidence-Governed Adversarial Assessment and Retesting
Abstract
AI agents increasingly operate through tools, memory, delegated authority, external information, persistent state, and multi-agent coordination. Penetration testing that focuses on one model endpoint or terminal action can therefore miss weaknesses that emerge across the wider agentic process.
This paper proposes an evidence-governed model for penetration testing of agents, agentic processes, and agent organizations. Controlled adversarial pressure is treated as a method of security-evidence acquisition whose findings remain bounded by the tested configuration, state, visibility, and execution conditions. The model binds test authority, target, baseline and test-instance state, adversarial action, observation paths, evidence, and claim limitations.
Because testing can itself alter persistent or adaptive state, test-exposed instances are treated as experimental artifacts rather than automatically reusable production artifacts. The paper separates test-induced adaptation from validated hardening and uses a clean-baseline retest loop for bounded mitigation claims.
Supporting elements include classical penetration-test dimensions adapted to agentic systems, differential reference-state testing, external-tester and replica-custody boundaries, third-party and federated agent trust boundaries, and penetration testing of agentic security controls through independently governed observation paths. The contribution is conceptual and does not introduce a new exploit technique, autonomous attack system, or empirical benchmark.
Key concepts
- Agentic process as the penetration-test target
- Governed adversarial testing as evidence acquisition
- Findings bounded by tested configuration, state, visibility, and execution conditions
- Test-state and evidence binding
- Test-induced adaptation separated from validated hardening
- Test-exposed instances treated as experimental artifacts
- Clean-baseline retesting
- Security controls themselves as penetration-test targets
Keywords
Agentic AI · AI Agents · Agentic Processes · Penetration Testing · Cybersecurity · AI Security · Adversarial Testing · Security Assessment · Multi-Agent Systems · Evidence-Governed Security · Retesting
Citation
Brömme, Arslan (2026). Penetration Testing for Agentic Processes: Evidence-Governed Adversarial Assessment and Retesting. Version v0.9.0.10. Zenodo. DOI: 10.5281/zenodo.22766559.
BibTeX
@misc{broemme2026agenticpentest,
author = {Arslan Brömme},
title = {Penetration Testing for Agentic Processes:
Evidence-Governed Adversarial Assessment and Retesting},
year = {2026},
month = sep,
version = {v0.9.0.10},
publisher = {Zenodo},
doi = {10.5281/zenodo.22766559},
url = {https://doi.org/10.5281/zenodo.22766559}
}