Why the pentesting playbook doesn’t fit: belief, assumptions, and non-determinism
ID: 496b02ba-9f7e-5b51-bc23-d9cf70864796
STIX ID: report--496b02ba-9f7e-5b51-bc23-d9cf70864796
Feed Name: NVISO Labs
This post explains why conventional security testing and pentesting approaches fail for AI systems: unlike deterministic software, AI behavior depends on training data, inference-time context, and non-deterministic generation, which makes exhaustive input/output testing ineffective. It highlights prompt injection as a prevalent and hard-to-solve risk, describes the need to test behavioral bounds and defense-in-depth (guardrails, output checks, least privilege), and situates the guidance within evolving regulatory expectations (EU AI Act, NIST AI RMF). The series will follow with concrete test guidance, examples, and a threat/coverage model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
