Skip to content
Pentesys
Knowledge Base
Announcements9 min read

Pentesys Signs the CREST AI Charter

Pentesys has signed the CREST AI Charter, reinforcing our commitment to the responsible, transparent and professionally governed use of artificial intelligence in cybersecurity.

Pentesys Testing Team · CREST-registered consultants

Pentesys Signs the CREST AI Charter

Pentesys signs the CREST AI Charter

Pentesys is proud to announce that it has signed the CREST AI Charter, reinforcing our commitment to the responsible, transparent and professionally governed use of artificial intelligence within cybersecurity.

Artificial intelligence is increasingly influencing how cybersecurity services are delivered, including penetration testing. Adoption is accelerating across analysis, reconnaissance, vulnerability triage and reporting. That adoption must not come at the expense of security, professional judgement, accountability or client trust.

Pentesys views AI as a technology that augments experienced cybersecurity professionals rather than replaces human expertise. Our testers use AI to work faster and cover more ground; they remain responsible for what reaches a client report.

CREST AI Charter Signatory badge alongside the Pentesys wordmark

What is the CREST AI Charter?

The CREST AI Charter is an industry initiative created by CREST to promote the responsible use of artificial intelligence within cybersecurity services. It brings together cybersecurity organisations that publicly commit to supporting responsible AI use and that recognise the importance of shared principles, professional standards and industry collaboration.

The Charter sits alongside the CREST AI Principles and CREST's wider programme of AI research, standards and accreditation, published through the CREST AI Hub and the CREST AI Charter page. CREST launched the Charter with a global cohort of around 60 founding signatory organisations spanning 15 countries, and continues to welcome further member and community signatories.

The Charter is a public commitment rather than an audit. It signals how an organisation intends to govern AI use; it does not by itself certify that an organisation's controls have been independently assessed.

Why has Pentesys signed the CREST AI Charter?

Pentesys believes AI has significant potential to improve cybersecurity services when it is implemented responsibly. Used carefully, AI already helps our consultants in several practical areas.

  • Increasing the efficiency of security analysis across large, noisy data sets.
  • Supporting reconnaissance and external attack surface analysis.
  • Identifying patterns within high volumes of security information.
  • Supporting vulnerability analysis and prioritisation.
  • Assisting penetration testers with repetitive, mechanical tasks.
  • Supporting reporting and remediation workflows.
  • Increasing the frequency with which organisations can assess their security posture.
  • Helping organisations move towards continuous security validation rather than annual snapshots.

AI should support penetration testers, not replace professional judgement

AI-generated information must always be appropriately reviewed and validated before it informs a security decision. Signing the CREST AI Charter reflects the Pentesys commitment to developing AI capabilities within appropriate governance, security and professional oversight.

Effective penetration testing continues to require experienced security professionals. AI can help testers work more efficiently, but the areas that determine whether a test is genuinely useful still depend on human judgement.

  • Business logic vulnerabilities that only make sense in the context of a specific application.
  • Complex attack chains built from individually low-severity issues.
  • Exploitability assessment: proving whether a theoretical weakness is actually reachable.
  • Contextual risk, based on what the affected system does for the business.
  • Authentication and authorisation weaknesses across roles, tenants and workflows.
  • Real-world impact rather than tool-assigned severity.
  • False-positive elimination before findings reach a client.
  • Client-specific context, including compensating controls and operational constraints.

Human-led. AI-supported. Evidence-driven.

Human-led. AI-supported. Evidence-driven. This is the Pentesys principle behind every engagement we deliver.

In practice, it means AI-supported output does not automatically become a client finding. Anything surfaced with AI assistance is technically validated by a Pentesys consultant, with evidence, before it is reported. Where AI cannot demonstrate impact, a human tester does — or the finding does not ship.

The importance of responsible AI in cybersecurity

AI requires particularly strong governance in cybersecurity because the information involved is unusually sensitive and the consequences of an unvalidated output are unusually high.

Data protection

Sensitive client information must be appropriately controlled wherever AI systems are involved, including how data is transmitted, where it is processed and whether it can be retained or reused.

Confidentiality

Security testing information can contain details of live vulnerabilities, infrastructure and viable attack paths. That material requires careful handling regardless of the tooling used to produce it.

Human oversight

AI outputs can be inaccurate, incomplete or confidently misleading. They should be reviewed by someone qualified to judge whether they are correct.

Transparency

Clients should be able to understand where AI materially contributes to the cybersecurity services they receive, and how those contributions are validated.

Accountability

Responsibility for professional cybersecurity decisions remains with accountable people and organisations. A model is not accountable; a consultant and their employer are.

Security of AI systems themselves

AI systems introduce their own security considerations, from prompt injection and data leakage to supply chain exposure. Organisations adopting AI need to understand and manage those risks as part of their wider security programme.

From AI principles to independent assurance

CREST's work has progressed beyond the voluntary AI Charter. CREST has introduced independently assessable AI requirements, published through the CREST AI Hub, covering Responsible AI Use — additional requirements within the Company General Requirements covering AI governance, accountability and oversight — and AI-Enabled Penetration Testing, which provides assurance that AI is used in penetration testing in a controlled, authorised and professionally supervised way. Further assurance covering security testing of AI, security operations, incident response, threat intelligence and threat-led penetration testing is signposted by CREST as coming soon.

These are separate from the Charter. Being a CREST AI Charter signatory is a public commitment to responsible AI principles. CREST AI accreditation is an independently assessed standard. Pentesys does not present its Charter signatory status as equivalent to those accreditations, and neither should any provider.

Pentesys and AI-enabled penetration testing

AI-enabled penetration testing, as Pentesys practises it, combines four things: human expertise, automation, AI and continuous visibility. Automation provides breadth and repeatability. AI accelerates analysis and triage across that output. Continuous visibility keeps the attack surface current between engagements. Human expertise decides what any of it means.

That combination supports a more continuous approach to security testing than isolated point-in-time assessments allow. It underpins our Penetration Testing as a Service delivery model, our AI penetration testing capability, and the exposure management workflow described on our CTEM page.

Findings, evidence, remediation status and retesting are managed in the Mirage portal, so clients can see how a finding was identified, who validated it and what changed after remediation. Traditional scoped engagements remain available through our penetration testing service.

Supporting the evolution of penetration testing

CREST published global research in 2026 examining how AI is used within professional penetration testing. Based on original research with 62 cybersecurity providers across 19 countries, CREST reports that 69% of respondents use AI in penetration testing workflows and 76% have increased their use over the past year.

CREST's AI in Penetration Testing research page records that 47% of organisations use AI for reporting and 44% for vulnerability scanning and enumeration, while only 9% report using autonomous, agent-based testing. CREST's own summary of the findings is that AI is not replacing penetration testers; it is reshaping how they work.

Rising adoption is exactly why governance and professional oversight matter more, not less. The likely direction of travel is security professionals working alongside increasingly capable AI and automation — with accountability, validation and client trust remaining human responsibilities.

What does this mean for Pentesys customers?

Practically, signing the CREST AI Charter means customers should expect Pentesys to approach AI in the following way.

  • Appropriate governance over how and where AI is used in service delivery.
  • Human oversight of AI-supported activity by qualified consultants.
  • Technical validation of findings before they are reported.
  • Security and confidentiality considerations applied to testing data.
  • Responsible data handling aligned with our privacy policy.
  • Transparency about where AI materially contributes to an engagement.
  • Professional accountability retained by Pentesys and its consultants.
  • Continued investment in cybersecurity expertise alongside AI capability.

A commitment to responsible innovation

Signing the CREST AI Charter represents another step in Pentesys' commitment to combining innovation with the professional standards expected of a modern cybersecurity provider.

Pentesys intends to continue developing AI-enabled cybersecurity capabilities while keeping human expertise, technical validation and client trust at the centre of service delivery.

Human-led. AI-supported. Evidence-driven.

About the CREST AI Charter

The CREST AI Charter brings together organisations committed to supporting the responsible use of artificial intelligence within cybersecurity and promoting principles including transparency, accountability and professional oversight. Further information is available on the CREST AI Hub.

About Pentesys

Pentesys is a UK cybersecurity company providing penetration testing, Penetration Testing as a Service (PTaaS) and continuous security testing services, delivered by CREST-registered consultants and managed through the Mirage portal. Pentesys Ltd is listed as a CREST member company for penetration testing.

FAQ: What is the CREST AI Charter?

The CREST AI Charter is an industry initiative led by CREST that brings together cybersecurity organisations publicly committing to the responsible use of artificial intelligence in cybersecurity services, based on shared principles including transparency, accountability and professional oversight.

FAQ: Is Pentesys a CREST AI Charter signatory?

Yes. Pentesys is a signatory of the CREST AI Charter, listed by CREST among its member signatories.

FAQ: What does being a CREST AI Charter signatory mean?

Being a CREST AI Charter signatory means an organisation has made a public commitment to the principles of responsible AI use established through the CREST initiative. It is a statement of intent and principle, not an independently assessed AI accreditation; CREST's Responsible AI Use and AI-Enabled Penetration Testing standards are assessed separately.

FAQ: Does Pentesys use AI for penetration testing?

Yes. Pentesys uses AI to support reconnaissance, attack surface analysis, vulnerability analysis, triage and reporting, within a human-led model. Findings identified with AI assistance are validated by Pentesys consultants with supporting evidence before they are reported to clients.

FAQ: Will AI replace penetration testers?

AI is augmenting penetration testers rather than replacing them. AI and automation handle volume, pattern recognition and repetitive analysis, while human expertise remains important for validation, contextual risk analysis, business logic testing, complex exploitation and professional judgement. CREST's 2026 research found only 9% of surveyed providers use autonomous, agent-based testing.

FAQ: What is AI-enabled penetration testing?

AI-enabled penetration testing is penetration testing in which artificial intelligence supports parts of the testing lifecycle — such as reconnaissance, enumeration, analysis, triage and reporting — while the engagement remains subject to appropriate human oversight, technical validation and professional accountability.

Keep reading

More from the knowledge base

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.