Wavestone, one of Europe’s leading independent consulting firms, published a landscape review of 69 agentic AI solutions for penetration testing on September 14, 2026. The research helps red teamers, professional pentesters and security auditors decide which AI tools to use. Read it in French or English.
Named among the most promising in Red Team
Red Team is the category where Wavestone sets the highest bar. Many tools use the label, but Wavestone found that only 13% of the 69 solutions actually show what it considers red team characteristics: finding a path to compromise with real control, stealth and adaptability. Pentera is named among the most promising solutions in this group. For a team building or scaling its red team, see how Pentera approaches automated red teaming.
Also named for internal and external pentesting
In the Infrastructure and Network category, covering internal and external pentesting, network mapping, privilege escalation and Active Directory, Wavestone lists Pentera among the interesting solutions.
That range matches how Pentera is used by enterprise security teams worldwide. The platform validates the cyber resilience of internal networks with Pentera Core, external assets with Pentera Surface, and cloud and hybrid environments with Pentera Cloud. It also tests web applications, all in production environments.
What Wavestone says about where the market is going
The review’s conclusions line up with how we think about AI in offensive security. Wavestone expects agentic solutions to augment professional auditors in the short term, with faster reconnaissance, broader coverage and automated re-testing to confirm that fixes hold. It also stresses that agents need to be kept within scope by technical controls, not just by instructions in a prompt – an unsupervised agent can send excessive requests, follow a redirect off-target, or use the wrong credential. Data confidentiality needs careful attention.
Safe execution is central to Pentera. The platform is built for controlled execution with audit proof, so security teams can test their cyber defenses in production with confidence. It shows which exposures are exploitable, moves validated findings into remediation workflows, and re-tests after fixes are made.
Thank you to the Wavestone team
Thank you to Theo Atakpama, Gregoire Podda and Thomas Rousseau for a thorough, useful review, and for including Pentera. It’s a good read for anyone weighing AI pentesting options, and the full radar and category reviews are worth the time.
See how Pentera brings automated pentesting and automated red teaming to your environment, or talk to an expert.
Category placements and descriptions in this post reflect Wavestone’s review published on the RiskInsight blog on September 14, 2026.
