Introduction
AI is changing how red teams work, and it’s an open question how far that goes. On the one hand, there is a future where we let an AI loose with a prompt like, ‘hack this environment like APT29.’ On the other, red teaming often involves access into core production systems where there is no margin for error. How do you capture the benefits of AI without it causing unintended damage?
In this talk, veteran red teamer Pieter Ceelen maps the risks and the open questions, and shares where he’s landed on balancing autonomy against control, whether you’re the operator running the engagement or the CISO who has to sign off on it. He’ll close with a preview of how this has begun to take shape in Cobalt Strike, demonstrating how AI can take real action on an engagement in a structure that keeps operators in command.