And “boom”—we just performed what would normally be an ugly penetration test using AI.

Here’s what we did:

  • Spun up an isolated Linux VM in the cloud, locked down with its own private network and security controls.
  • Deployed a Claude AI coding assistant with a simple set of instructions defining our target and scope.
  • Let it loose.

What happened next was genuinely impressive. It worked methodically through reconnaissance, active scanning, and vulnerability testing. It found things I had not seen flagged before and produced clear, detailed findings without us lifting a finger.

Does this replace an external penetration test?

Absolutely not.

We still want the separation, independence, and accountability that only a third party can provide.

But the feedback loop has changed. We can now discover the good and bad news internally, faster, before we submit a system for external inspection—and at essentially no additional cost.

The bar for internal security validation just dropped dramatically. If your team is not experimenting with this yet, it probably should be.

Originally published on LinkedIn.