Blog

min read

Pillar launches Red Graph Suite: version-controlled, contextual and continuous AI red teaming

By

Dor Sarig

and

August 6, 2026

min read

Red Graph is now a full suite covering the entire AI red-teaming lifecycle. The new suite runs autonomous attacks through an AI agent's real interface, proves what was executed, and tracks how every release changes what an attacker can do.

Today Pillar Security launched Red Graph Suite, an all-in-one platform for the full AI red-teaming lifecycle. Red Graph Suite maps an AI system's attack surface, runs autonomous adversarial tests against the live application, proves what was actually executed, and tracks security posture across every release the way engineers track a test suite.


What Red Graph Suite does:

  • Maps the attack surface. Autonomous reconnaissance captures an agent's system prompt, tools, knowledge, and permissions with no code changes, and tracks how they change release to release, so a newly exposed tool or a loosened rule shows up as a diff.
  • Tests through the real app interface. Rather than sending prompt libraries to a model endpoint, autonomous agents run multi-turn attacks through the application's own UI, navigating workflows, invoking tools, and chaining individually safe capabilities into real exploits.
  • Proves what executed. Every finding ships with a video of the attack, a step-by-step log of the agent's actual actions, and the full conversation, turning "the model said something bad" into "here is the command that ran."
  • Tracks posture over time. A version-controlled view scores attack success rate per objective per release, labels each as stable, newly found, hardened, or regressed, and surfaces regressions the moment they appear.
  • Maps to the frameworks auditors ask for, including the OWASP Agentic AI and LLM Top 10s, MITRE ATLAS, NIST's AI Risk Management Framework and Pillar’s SAIL framework.

Every AI red-team report carries a hidden expiration date

For the past two years, the industry has treated AI red teaming as an audit. Commission a test, receive a PDF, and file it away. The approach borrowed its shape from traditional penetration testing, and it made a kind of sense while AI deployments were pilots.

But a point-in-time assessment of an AI system describes a version that no longer exists. A conventional application changes when engineers change it. An AI application changes when anyone edits the prompt, adds a tool, updates the knowledge base, or when the model provider ships an update nobody asked for. A defense that held last week can silently break with any of those changes, and no annual test will see it happen.

In a recent assessment, an autonomous attacker went to work on an AI helpdesk agent, the kind of tool thousands of companies now run to handle IT tickets. Instead of firing a list of prompts at a model endpoint, it logged in and worked through the chat interface like a patient adversary. Within minutes it had talked the agent into running shell commands on the host, leaking internal data through a fetched web page, and executing database queries it had no business running. Of 17 attack objectives, 15 succeeded.

The part that matters came next: the attacker ran the same 17 objectives against the next release of that agent, and the one after that, six versions in all, and drew a map of which defenses held, which broke, and which quietly regressed after a "fix."

That map is what Red Graph Suite produces for every release.

For a while, teams could live with the gap between one-time testing and systems that change weekly. Three things closed off that option in the twelve months leading to this launch.

Agents reached production scale. Gartner predicts that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from under 5% in 2025. Most security teams will inherit an agentic attack surface this year, whether they planned for it or not, and an agent that executes commands and queries databases carries a different class of risk than a chatbot that generates text.

Attacks left the lab. In December 2025, Palo Alto Networks' Unit 42 documented the first in-the-wild indirect prompt injection campaign, built to slip hostile instructions past an AI review system. By March 2026, the same team had cataloged 22 distinct injection techniques used in live attacks, aimed at data theft, unauthorized transactions, and data destruction. OWASP's 2026 State of Agentic AI Security report now maps prompt injection to six of the ten categories in its Agentic Top 10. Prompt injection stopped being a conference demo and became a crime with victims.

Regulation put dates on the calendar. The EU AI Act's obligations for high-risk AI systems apply from August 2, 2026, and they require evidence of resilience to attack. "We ran a red team last spring" won't satisfy an auditor asking about the system you shipped last week.

Each signal is small on its own. Together they mark the moment AI security tips from an audit you schedule into a practice you run. Red Graph Suite is the instrument that practice runs on.



"Security teams kept telling us the same thing: a point-in-time red-team report for AI systems is out of date before the next update ships," said Dor Sarig, Co-founder and Chief Product Officer at Pillar Security. "They didn't want another scan. What they wanted was a system of record - somewhere they could watch their AI's security posture move, catch the regression before it reached production, and prove exploitability to a developer who'd otherwise argue the finding away. That's what Red Graph Suite is."


Findings flow directly into the rest of Pillar's platform, closing the loop from discovering an attack path to enforcing a policy against it.

Red Graph, the technology underneath the suite, earned a place among Gartner's Coolest Vendor Innovations in AI Software Security in July 2026 for mapping live AI environments as an attack graph and simulating an attacker's pivots through chains of tool calls and prompt injections. Worth noting: "AI Software Security" is now a named analyst category. Analysts create categories when buyers start asking the same questions again and again.

The one-time AI red team had its era. The systems it tested now change too fast for it, the attackers it anticipated now work multi-turn and in the wild, and the auditors it satisfied now ask which version you tested.

See Red Graph Suite in action

Subscribe and get the latest security updates

Back to blog

MAYBE YOU WILL FIND THIS INTERSTING AS WELL

ChainDrop: When Opening a Repository Becomes Execution

By

Ariel Fogel

and

August 4, 2026

Research
I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository

By

Dan Lisichkin

and

August 3, 2026

Research
Our CTF Mapped an AI Killchain. Days Later, It Appeared in Hugging Face’s Production Environment.

By

Ariel Fogel

and

July 30, 2026

Blog