Analysis · curated 3 Oct 2026

Why an LLM Alone Cannot Run an AI Penetration Test

Coverage timeline

30 Sep 2026firecompass.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Agentic AI security highlights that even well-aligned LLMs become risky once equipped with tools and autonomy, meaning defenders must govern agent trajectories—not just model outputs—to prevent autonomous systems from exceeding intended scope.

FireCompass analysis argues that model safety is not agent safety: an autonomous AI penetration-testing agent can chain individually-permitted actions (recon, exploitation, credential discovery, lateral movement) into an overall trajectory nobody intended, leaving the agent 'somewhere it was never supposed to be.' The piece contrasts frontier-model capability evaluations (OpenAI Preparedness Framework, Google DeepMind Frontier Safety Framework) with the downstream gap of controlling agent behavior once a model is given memory, tools, credentials, a shell, and an objective.