Penetration Testing for Agentic Processes:
Evidence-Governed Adversarial Assessment and Retesting

Arslan Brömme

Abstract

AI agents increasingly operate through tools, memory, delegated authority, external information, persistent state, and multi-agent coordination. Penetration testing that focuses on one model endpoint or terminal action can therefore miss weaknesses that emerge across the wider agentic process.

This paper proposes an evidence-governed model for penetration testing of agents, agentic processes, and agent organizations. Controlled adversarial pressure is treated as a method of security-evidence acquisition whose findings remain bounded by the tested configuration, state, visibility, and execution conditions. The model binds test authority, target, baseline and test-instance state, adversarial action, observation paths, evidence, and claim limitations.

Because testing can itself alter persistent or adaptive state, test-exposed instances are treated as experimental artifacts rather than automatically reusable production artifacts. The paper separates test-induced adaptation from validated hardening and uses a clean-baseline retest loop for bounded mitigation claims.

Supporting elements include classical penetration-test dimensions adapted to agentic systems, differential reference-state testing, external-tester and replica-custody boundaries, third-party and federated agent trust boundaries, and penetration testing of agentic security controls through independently governed observation paths. The contribution is conceptual and does not introduce a new exploit technique, autonomous attack system, or empirical benchmark.

Key concepts

  • Agentic process as the penetration-test target
  • Governed adversarial testing as evidence acquisition
  • Findings bounded by tested configuration, state, visibility, and execution conditions
  • Test-state and evidence binding
  • Test-induced adaptation separated from validated hardening
  • Test-exposed instances treated as experimental artifacts
  • Clean-baseline retesting
  • Security controls themselves as penetration-test targets

Keywords

Agentic AI · AI Agents · Agentic Processes · Penetration Testing · Cybersecurity · AI Security · Adversarial Testing · Security Assessment · Multi-Agent Systems · Evidence-Governed Security · Retesting

Citation

Brömme, Arslan (2026). Penetration Testing for Agentic Processes: Evidence-Governed Adversarial Assessment and Retesting. Version v0.9.0.10. Zenodo. DOI: 10.5281/zenodo.22766559.

BibTeX

@misc{broemme2026agenticpentest,
  author       = {Arslan Brömme},
  title        = {Penetration Testing for Agentic Processes:
                  Evidence-Governed Adversarial Assessment and Retesting},
  year         = {2026},
  month        = sep,
  version      = {v0.9.0.10},
  publisher    = {Zenodo},
  doi          = {10.5281/zenodo.22766559},
  url          = {https://doi.org/10.5281/zenodo.22766559}
}