Skip to main content
Packetlabs Company Logo
Technical

How Does Packetlabs Make its AI Use Clear to Clients?

Authored By Denis Kucinic, VP of Operations

How Does Packetlabs Make its AI Use Clear to Clients?

Would you like to learn more?

Download our Pentest Sourcing Guide to learn everything you need to know to successfully plan, scope, and execute your penetration testing projects.

Clients hand penetration testers deep access. Source code, live production systems. As AI becomes part of how that work gets done, they deserve to know how it's governed before an engagement starts, not after. So we put it in writing in line with the CREST AI Charter.

Artificial intelligence has rapidly become part of the modern penetration testing toolkit: it can accelerate research, streamline documentation, improve analysis, and reduce repetitive manual work. However, as AI becomes more integrated into professional security services, a new question has emerged:

How do clients know their security provider is using AI responsibly?

Until recently, most AI guidance in cybersecurity focused on testing AI systems themselves. Organizations wanted assurance that their own large language models (LLMs), AI-powered applications, and machine learning platforms were secure against prompt injection, data leakage, jailbreaks, and other emerging attack techniques.

CREST's 2026 accreditation standards introduce a different conversation altogether.

For the first time, accredited penetration testing firms are expected to demonstrate not only how they test AI systems, but also how they govern their own internal use of AI while delivering client engagements.

This represents an important evolution for the penetration testing industry.

At Packetlabs, this wasn't a change in how we perform assessments: it was a change in how we document those practices.

Our AI governance is now transparent, auditable, and contractually binding. Rather than introducing new operational policies, the revisions formalize practices that were already embedded within our internal AI Use Policy, quality assurance processes, and security controls.

Here's what changed (and how it impacts our clients.) 

CREST's 2026 AI Governance Standards Explained

CREST added two things to its accreditation framework, and they don't carry the same weight.

The first is AI-Enabled Penetration Testing. It's an optional annex. A provider adopts it to demonstrate assurance over how AI is used in the delivery of testing, and it only applies when the provider seeks that recognition. It isn't mandatory, and it isn't part of the baseline penetration testing standard unless a provider adopts it or a specific accreditation pathway requires it. Where it is adopted, it sits alongside the Company General Requirements and the Penetration Testing Accreditation Standard, not on its own.

The second is Domain 7: Responsible AI Use, inside the CREST Company General Requirements. This one is baseline. It sets out how an organization uses AI in a governed and responsible way wherever that use could affect client confidentiality, service delivery, client-facing outputs, legal obligations, or professional judgement. CREST defines that use broadly. AI is "material" whenever it touches client information, credentials, logs, screenshots, source code, vulnerability evidence, or client environment information, whether the AI processes it, generates it, or just summarizes it.

Both are often confused with CREST's Security Testing of AI supplement, which does something else entirely.

The supplement is about testing an AI system as the target of an assessment. Risks like:

Domain 7 and the AI-Enabled Penetration Testing annex point the other way. They don't govern how a tester evaluates a client's AI system. They govern how a testing firm uses AI on its own side of the engagement, while handling the client's most sensitive information.

That distinction matters.

The industry has traditionally asked: "Can your penetration tester evaluate our AI application?"

CREST now also asks: "Can your provider prove they're using AI responsibly while holding our source code, credentials, and findings?"

For anyone evaluating a security vendor, that's a new axis of due diligence.

What Domain 7 Requires

Domain 7 establishes baseline organizational governance for responsible AI use. It requires accredited organizations to maintain documented controls whenever AI could materially affect:

  • Client confidentiality

  • Service delivery

  • Professional judgment

  • Client-facing deliverables

  • Legal obligations

  • Security of engagement information

Importantly, CREST defines material AI use broadly.

This includes AI interacting with:

  • Source code

  • Credentials

  • Vulnerability evidence

  • Logs

  • Security artifacts

  • Screenshots

  • Client documentation

  • Personal information

  • Assessment findings

Organizations must also maintain approved AI usage policies, restrict unauthorized tools, establish oversight mechanisms, and ensure employees understand both the strengths and limitations of AI-assisted workflows.

Shadow AI is no longer simply an internal IT concern.Under CREST's framework, uncontrolled AI usage can become an accreditation issue.

Understanding Annex B for AI-Enabled Penetration Testing

While Domain 7 governs organizational AI usage, Annex B focuses specifically on AI-assisted penetration testing.

It introduces six major areas organizations must demonstrate.

PT-AI.1: AI Within the Testing Methodology

Organizations must clearly define where AI fits into the penetration testing methodology and ensure qualified professionals remain responsible for assessment outcomes.

PT-AI.2: Scope, Authorization, and Rules of Engagement

AI-assisted activities must remain within the approved scope of the engagement.

AI should never create unauthorized testing activities or expand assessment boundaries without client approval.

PT-AI.3: Protection of Penetration Testing Data

Organizations must demonstrate appropriate controls over any client data processed through AI-enabled workflows.

This includes confidentiality, storage, processing, and jurisdictional controls.

PT-AI.4: Control of AI-Generated Offensive Content

AI-generated attack content requires governance.

Organizations must prevent unsafe or uncontrolled offensive outputs from being used against production systems.

PT-AI.5: Validation of AI-Assisted Findings

Perhaps the most important requirement is that AI cannot determine findings independently.

Severity ratings, exploitability assessments, vulnerability validation, and prioritization remain the responsibility of qualified penetration testers, and must be reflected in final reports.

PT-AI.6: AI-Assisted Reporting and Remediation

Organizations may use AI to accelerate reporting and remediation guidance, but every deliverable must undergo expert review before reaching the client.

AI-Enabled Penetration Testing also explicitly excludes fully autonomous offensive AI activity.

Human supervision is not optional.

Qualified testers remain accountable throughout every engagement.

Why These Cybersecurity AI Standards Represent an Industry Turning Point

For years, discussions around AI governance in cybersecurity focused almost exclusively on protecting organizations from AI-related threats. CREST broadens that conversation.

Now, security firms themselves must demonstrate responsible AI governance.

That is a healthy evolution. Clients routinely trust penetration testing providers with some of their organization's most sensitive information, including:

  • Internal network architecture

  • Source code

  • Authentication systems

  • Administrative credentials

  • Vulnerability evidence

  • Production infrastructure

  • Proprietary business information

As AI becomes part of professional workflows, organizations deserve transparency regarding how that information is processed.

Responsible AI governance is becoming another trust signal alongside certifications, quality assurance processes, and security attestations.

Packetlabs' Starting Position

We modified our documentation and internal processes to ensure it accurately reflected CREST AI practices.

Packetlabs has also modified internal policies governing AI usage.

Those policies emphasized:

  • Human oversight

  • Confidential data protection

  • Approved tooling

  • Controlled workflows

  • Secure processing

  • Professional accountability

Our existing operational foundation already included:

  • CREST certification

  • SOC 2 Type II attestation

  • Mature confidentiality controls

  • Secure client data handling

  • Established quality assurance processes

Rather than asking clients to assume responsible AI practices exist behind the scenes, we now describe them directly within the engagement documentation.

Why? Because transparency builds trust.

What’s Been Enhanced in the Packetlabs Delivery

1: AI Tooling is Explicitly Documented

Clients deserve visibility into every significant technology supporting an engagement.

Our AI usage follows several core principles:

  • Data remains region-pinned

  • Client information never leaves the approved jurisdiction

  • Data is never used to train public or third-party AI models

  • Client information is never submitted to consumer AI services such as ChatGPT, Microsoft Copilot, or other public generative AI platforms

Most importantly, AI accelerates work; it doesn’t replace qualified penetration testers. The expertise, judgment, validation, and accountability remain entirely human.

Why This Matters

Clients should never finish a penetration test only to discover AI was involved without their knowledge.

Transparency eliminates surprises. It also enables procurement teams, compliance reviewers, and security leaders to evaluate AI governance before work begins.

2: Data Residency Now Includes AI Processing

Many organizations already ask where penetration testing data will be stored.

Increasingly, they also ask where AI processing occurs.

For Canadian engagements, AI processing remains within Canada; for U.S. engagements, processing remains within approved U.S. regions; and so on and so forth. 

This applies equally to storage, infrastructure, and AI-assisted processing. An equally important addition is what happens when compliant AI processing isn't available.

The answer is simple: the AI-assisted activity does not occur.

There is no automatic fallback to another jurisdiction. There is no exception based on convenience.

Client residency commitments always take priority.

Why This Matters

Organizations operating under privacy regulations, contractual obligations, or industry-specific compliance frameworks increasingly require strict geographic control over sensitive information.

AI should not become an unexpected exception.

By extending residency commitments to AI processing, we close a gap many clients may not have realized existed.

3: Responsible Use of AI

Rather than simply referencing CREST guidance, this section operationalizes it through-out the entire client journey.

It establishes clear commitments governing every AI-assisted engagement.

Human Oversight

Every AI-assisted output remains under direct human review.

AI may accelerate research, summarize information, or assist documentation. It never independently determines findings.

Qualified penetration testers retain responsibility for every assessment conclusion.

Approved Tooling Only

Only approved AI tools may be used during client engagements. Personal AI accounts, unauthorized services, or shadow AI platforms are prohibited.

This significantly reduces governance risk.

Secure Data Handling

Client information remains protected according to the agreed jurisdictional requirements. No client data is used to train third-party AI models.

Security controls extend across every AI-assisted workflow.

Transparency

When AI materially contributes to engagement delivery, clients know.

Responsible AI governance should never depend on hidden processes.

Auditability

AI usage remains documented and traceable.

This supports internal quality assurance, external audits, and accreditation requirements.

Manual Fallback Procedures

Technology occasionally becomes unavailable.

If an approved AI service experiences an outage during an engagement, our methodology continues through established manual processes.

Service delivery does not depend exclusively on AI availability.

An Important Distinction

This Responsible Use of AI section governs how Packetlabs uses AI while delivering penetration testing services.

It does not describe AI penetration testing services performed against client AI applications.

Those are separate service offerings with different objectives.

Keeping those concepts distinct avoids unnecessary confusion during procurement and project scoping.

4: Production-Safe Testing Includes AI Controls

Packetlabs has always emphasized production-safe testing.

Existing safeguards include:

  • Controlled scanner throughput

  • Continuous latency monitoring

  • Immediate escalation of suspicious activity

  • Annual production-safe methodology training

The updated delivery model now adds two AI-specific controls.

First, AI-assisted testing only occurs under direct supervision of qualified penetration testers.

Second, every AI-generated output is manually validated before influencing any assessment finding.

These additions reinforce an important principle: that automation never bypasses professional judgment.

The qualified tester remains responsible from initial reconnaissance through final reporting.

Why These Changes Matter for Clients

Some organizations may view AI governance as another compliance checkbox. We see it differently.

Explicit AI governance benefits clients in several practical ways: 

Enhanced Transparency

Clients understand exactly how AI may support their engagement.

There are no hidden workflows or undocumented technologies.

Stronger Data Protection

AI processing follows the same jurisdictional commitments as every other aspect of the assessment.

Improved Accountability

Human experts remain accountable for every finding, recommendation, and report.

Easier Procurement Reviews

Security, legal, procurement, and privacy teams increasingly evaluate vendor AI governance.

Documenting these controls simplifies that review process.

Greater Audit Readiness

Clear documentation supports regulatory reviews, internal audits, and compliance initiatives.

Responsible AI is Becoming a Trust Requirement

Cybersecurity has always been built on trust.

Organizations trust penetration testing firms with privileged access, sensitive information, and critical infrastructure.

As AI becomes more common throughout professional services, clients deserve equal confidence in how that technology is governed. CREST's 2026 standards recognize that reality.

Rather than focusing solely on technical capabilities, they emphasize responsible operational practices.

That is an important shift for the industry.

AI can improve efficiency; it can accelerate analysis and enhance documentation. But it can’t replace professional judgement. 

Responsible governance ensures it never attempts to.

Packetlabs' Commitment to the CREST AI Charter

By aligning our engagement documentation with CREST's Responsible AI framework, we reinforce principles that have always guided our work:

  • Human expertise remains central

  • Client confidentiality comes first

  • AI operates within controlled, approved workflows

  • Transparency builds trust

  • Security assessments remain accountable to qualified professionals

As AI governance continues to evolve, Packetlabs will continue monitoring updates from CREST and other industry bodies to ensure our policies, procedures, and client documentation evolve alongside recognized best practices.

Combined with our CREST certification and SOC 2 Type II attestation, these updates reflect our ongoing commitment to delivering high-quality penetration testing with security, accountability, and transparency at every stage of the engagement.

If you'd like to learn more about our the updated Responsible Use of AI during engagements section or request a copy of our latest Statement of Work during the scoping process, contact Packetlabs. We're always happy to discuss how our security, governance, and AI practices support your organization's requirements.

Frequently Asked Questions

What are CREST's AI governance requirements?

CREST's 2026 accreditation framework introduced Domain 7: Responsible AI Use and AI-enabled penetration testing.

These standards govern how accredited penetration testing firms use AI internally while delivering client services, including data protection, human oversight, approved tooling, and quality assurance.

Is this the same as testing AI applications?

No. CREST distinguishes between testing client AI systems and governing a penetration testing firm's own use of AI.

Does Packetlabs use public AI tools like ChatGPT with client data?

No. Packetlabs' approved AI tooling does not submit client data to public or consumer AI platforms, and client information is never used to train third-party AI models.

Does AI replace Packetlabs penetration testers?

No. AI is used to improve efficiency by assisting with research, analysis, and documentation. Qualified penetration testers validate every AI-assisted output and remain responsible for every finding, severity rating, recommendation, and final report.

How does Packetlabs protect data residency during AI processing?

The same geographic residency commitments that apply to infrastructure and storage also apply to AI-assisted processing. If compliant AI processing cannot occur within the required jurisdiction, the AI-assisted activity is not performed.

Can clients request a fully manual penetration test?

Yes. Clients may request that AI-enabled tooling not be used during their engagement. Because this changes project assumptions, the assessment is rescoped and re-quoted before work begins.

Why is AI governance becoming important in penetration testing?

Organizations increasingly expect security providers to demonstrate responsible handling of sensitive information throughout every aspect of an engagement. AI governance improves transparency, accountability, compliance readiness, and client confidence while ensuring human expertise remains central to every penetration test.

Join our newsletter

Packetlabs Company Logo
  • Toronto | HQ401 Bay Street, Suite 1600
    Toronto, Ontario, Canada
    M5H 2Y4
  • San Francisco | Outpost580 California Street, 12th floor
    San Francisco, CA, USA
    94104
  • Calgary | Outpost421 - 7th Ave SW, Suite 3000
    Calgary AB, Canada
    T2P 4K9
  • Australia | OutpostPacketlabs Pty Ltd.
    ABN 14 691 178 542
    Level 24, 1 O'Connell St
    Sydney NSW 2000
Cyber Right NowCREST LogoCREST AI Signatory AICPA SOC 2 LogoG2Clutch 2023 Certification Logo