SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Every vendor calls their product an “agent.” But a read-only search tool, an API caller that waits for approval, and an autonomous system that can touch production are fundamentally different risk profiles—even when the marketing pages look identical. Without a shared vocabulary for autonomy, security teams end up applying Assistant-level controls to Agent-level capabilities, and boards end up approving deployments nobody fully understands.
The 4A Framework maps AI capabilities to four distinct autonomy levels—Assistant, Adjuvant, Augmentor, and Agent—each with its own risk profile and control requirements. Between Adjuvant and Augmentor sits the DANGER CLOSE boundary: the point where AI stops suggesting and starts acting, and where most organizations are deploying faster than their governance can keep up.
This session walks through the model, shows how to use it to cut through vendor terminology, and offers honest guidance on where most organizations should actually be operating today versus where the pitch decks say they should be.


Seth, SANS Faculty Fellow and author of SEC411, LDR414, and SEC511, combines cutting-edge consulting and education to equip defenders worldwide. Founder of Context Security and GSE #28, he brings clarity, humor, and purpose to cybersecurity training.
Read more about Seth MisenarSANS Nashville Summer 2026 offers world-class, hands-on cybersecurity training led by expert instructors who bring real-world experience directly to the classroom.
