VibeCoded

AI penetration testing for LLM apps

An AI penetration test is a standard application penetration test with the AI feature in scope: the login, roles, API and infrastructure, plus the prompts, retrieval and tools the model can reach.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

An AI penetration test costs $8,000 to $35,000 CAD and produces the report most customers and auditors mean when they ask for "a pentest". It tests the application an AI feature lives in, with authenticated access for each role, and adds the AI-specific attacks: prompt injection, data disclosure through the model, and tool abuse. The AI part rarely stands alone. A prompt injection that reaches a tool with an over-broad API key is an application finding as much as a model one.

Why the app and the model get tested together

The serious findings in AI products sit on the boundary. The model is asked to summarise a document, the document carries instructions, the model calls an internal API, and the API trusts the caller because it came from inside. Test the model alone and you see an injection with no consequence. Test the app alone and you see an API that looks locked down. Test them together and you see the path. The AI security assessment alone suits features with no tools and no customer data.

What a scope looks like

Typical AI penetration test scope
In scopeDetail
Web applicationEvery role, authenticated, including tenant isolation
APIEvery endpoint the front end and the model call
AI featurePrompt injection, system prompt leakage, data disclosure, output handling
Agent toolsEach tool's permissions and whether the model can be steered to misuse it
Cloud configurationStorage, keys and network exposure, if agreed
RetestVerification of fixes within an agreed window

The report a buyer accepts

A customer's security team wants three things: that the test was done by someone independent, that it covered the product they are buying, and that the serious findings were fixed. Ask for a report with an executive summary you can share, or a summary letter that confirms the scope, the dates and the retest without disclosing the findings. See using the report for SOC 2, and for the general case the report or attestation letter comparison on GetPentest.

What it costs

AI penetration testing, CAD, 2026
ScopeTypical range
Small app, one AI feature, two roles$8,000 to $15,000
Multi-tenant SaaS with retrieval over customer data$15,000 to $25,000
Agents with tool access, several integrations$20,000 to $35,000

These follow day-rate arithmetic: $1,500 to $2,800 CAD a tester day times the days the scope needs. The whole method is on testing costs in Canada. TrazTech scopes these through its AI security assessments and conventional penetration testing together.

Scope the test your customer asked for

Paste in what the customer or auditor wrote, and describe the product.

Get matched

Common questions

Is "AI penetration testing" a recognised standard?

Not as a standard of its own. It is an application penetration test that includes LLM attacks, usually mapped to the OWASP Top 10 for LLM applications. Ask any firm what their AI testing adds to a normal pentest.

Our AI feature is small. Can we leave it out of scope?

You can, but say so in the report. A buyer who later finds an untested AI feature in the product will ask why.

How long does it take?

One to four weeks from scoping to report, with five to fifteen testing days depending on size.