Carefully defining and subsequently adhering to an approved scope is arguably the most important qualitative aspect of any penetration test. A poorly scoped pentest is, at best, wasted time and expense—and at worst, a route to an unrecoverable security incident and permanent data loss. It is therefore a key element of modern pentesting and a critical, underappreciated input for AI-delivered pentesting.
And it's the part that AI vendors talk about least. That silence deserves scrutiny, particularly as the industry debates what continuous offensive security actually requires in practice.
The Brief: More Than a Starting Point
The most successful commercial pentesting providers have spent years refining scoping into its own science. Well-structured information gathering workflows bring together the raw measurable artifacts (number of hosts, IP address ranges, number of user accounts), functional business context (financial payment system, internal package routing system), security objectives (pre-FedRAMP preparation, procurement compliance), and testing constraints (blackout periods, DoS exclusions) into a single documented "Brief" — signed off and agreed by all parties before the pentest begins.
As much as people tiptoe around it, every pentesting engagement is a negotiated balance between price and effort. Given an infinite amount of time and an infinite number of monkeys, it is theoretically possible to find every vulnerability and exploit path in a target system. The scoping process and the Brief capture the reasonable efforts and directions of effort the pentester will deliver, and the anticipated value to the customer.
That said, to paraphrase Helmuth von Moltke the Elder: no plan survives first contact with the enemy.
The Real Work Happens Mid-Pentest
A secret of success often lies in the interaction between pentesters and the customer while the pentest is being conducted. As new findings surface, the scope can and should morph — within reason — to focus on the most impactful and valued customer objectives.
The customer may have anticipated their application would be littered with cross-site scripting (XSS) vulnerabilities, a class of flaw I've been writing about since the early days of web application security research, and already have a mitigation plan in place. But the discovery of weak ciphers in their session tokens was wholly unexpected, and they'd prefer the testers focus time and effort on diving deeper into session management rather than individually enumerating and validating a hundred-plus XSS findings. That kind of in-flight redirect is natural and valuable in human-led engagements, and it's exactly the kind of dynamic judgment that autonomous AI systems struggle to replicate today.
How AI Will (and Won't) Change Scoping
Scoping and Brief creation processes are a proven technology in the PTaaS world, refined over more than a decade. The step-by-step information-gathering process works well for humans. But several changes are coming.
As customers build out AI-assisted workflows of their own, it is reasonable to expect that AI operating on the customer's behalf will be providing pentest scope and requesting engagements in the future, making API options for Brief submission increasingly important for any pentesting provider.
The standard scoping process also has a well-known weakness: it can be laborious, and it sometimes struggles to capture the subtle directions and priorities embedded in a customer's testing requirements. That subtlety is currently captured through human processes — conversations with the pentest manager before kickoff, or with the pentester as the engagement begins. As customers grow more comfortable with AI-driven technical interfaces, interactive scoping that simulates a Q&A briefing call—and captures the nuance and priorities of the customer's objectives— becomes a realistic near-term alternative.
There is also the common situation where the person requesting the pentest simply does not have sufficient knowledge of the target to answer many of the technical scoping questions. Often they have documents they can share (architectural diagrams, configuration files, source code repository links) and will pass that bulk information to the PTaaS provider to interpret. This is a natural fit for AI: document-based scoping analysis that helps guide customers in resolving information gaps before testing begins.
The HitL Problem Isn't Going Away
Modifying scope mid-engagement is straightforward when humans are doing the work. It introduces real challenges when the pentest is fully automated or delivered by an autonomous agent operating without oversight.
The most viable path today runs through "human in the loop" (HitL), an approach where a human oversees and steers the agentic system, adjusting test parameters as findings emerge and keeping execution within guardrails. For that reason alone, HitL is a key component in delivering good-to-great quality pentesting with autonomous systems. It is not a concession to current AI limitations so much as an honest acknowledgment of where genuine expertise still lives. The Cobalt Autonomous Pentest product reflects exactly this design principle, and the 2026 State of Pentesting Report offers concrete data on how customers are navigating the human/AI balance in practice.
At some point, multi-agent approaches will be sufficiently advanced to dynamically interact with customers, absorb feedback mid-engagement, and redirect testing effort without a loss of quality or an overrun on budget. That point is not today.
Until it is, the Brief remains what it has always been: not a contract for how the pentest will unfold, but a carefully negotiated starting position. The best pentests — human or AI-led — treat it that way. That lesson predates AI by decades, as anyone who watched early pentesting methodology evolve into the discipline it is today will recognize. The VB2013 presentation on pentesting with live malware was one early marker of how scope and methodology had to stretch to accommodate new realities — and the AI era is simply the latest version of that same pressure.