Terra Sends AI Agents Into The Internal Network. The Liability Question Stays Outside

Estimated reading time: 9 minutes

Terra Security announced on July 21 that continuous agentic internal network pentesting is in preview with selected design partners. The capability extends the company’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says that makes it the first agentic offensive security provider running continuously across all four surfaces.

The claim is worth stating precisely. The internal network capability is in limited preview, not general availability, with a waitlist open. The “first across four surfaces” line rests on a product customers cannot yet buy.

Chief Executive Officer and Co-Founder Shahar Peled framed the expansion as a gap in industry practice. “Attackers do not stop at the perimeter, and neither should Offensive Security,” he said. He added enterprises can now answer a question that matters more than a vulnerability count: “If adversaries attack me today, what can they achieve?”

Why The Internal Network Went Untested

Terra’s case for the expansion is operational. Traditional internal testing often requires staff on site or persistent virtual private network access. It needs scoping negotiations and a fixed test window. The result is a snapshot of an environment that has already changed.

The company argues that infrastructure-as-code, continuous integration pipelines, and AI tooling now reshape internal topology faster than annual assessments can track. That argument is not controversial. It is the same pressure CINI covered in Contrast Security’s CVE Shield launch, where AI systems convert public vulnerabilities into working exploits faster than teams can patch.

Terra says hundreds of specialized agents work in parallel, triggering when code or infrastructure changes. Agents chain findings across surfaces the way an attacker would. Researchers oversee them through a control hub the company calls TORCH.

The Architecture Answer

CINI asked Terra what happens if an agent causes an outage in a production internal network. Is that a client business interruption loss or a Terra errors and omissions claim?

Peled rejected the premise before answering. He said the question assumes fully autonomous agents running unattended, and that Terra’s architecture was built specifically to avoid that. Engagements carry defined objectives, bounded toolsets, and customer-approved rules of engagement. Agents are not routed to the newest available model by default.

Peled described three guardrail layers. The foundation model’s own controls sit at the base. Terra’s platform-level controls sit above them and are deliberately not AI-based. Customer-specific controls sit on top. He argues the middle layer carries the weight, because “the enforcement of Terra’s core safety rules does not depend on the judgment of the same non-deterministic system it is governing.”

Then came a candid line. “No one working with non-deterministic technology can promise 100% predictability, and any vendor who does should not be trusted,” Peled said.

See also  Netwrix Strengthens Hybrid Security with Entra ID Integration, Aiming to Meet Evolving Cyber Insurance Requirements

An Industry Pattern, Not A Product Feature

Shahar Peled, Co-Founder and CEO of agentic pentesting firm Terra Security, smiling with arms crossed against a white background. Article for cyber insurance news.
Shahar Peled, Co-Founder and CEO of Terra Security

That architecture will sound familiar to readers of last week’s CINI coverage. PortSwigger launched Burp AT on July 27, built on the same principle. Agents propose actions. A deterministic control layer, architecturally separate from the model, decides what executes.

Two vendors reached the same conclusion within a fortnight. The model cannot be trusted to police itself, so a rule-based layer polices it instead. For underwriters assessing agentic tooling, that convergence is more useful than either company’s marketing. It suggests a control standard is forming in offensive security, and it gives risk engineers something specific to ask about.

The Third-Party Risk Question

CINI put the vendor dependency question to Terra directly. Agent swarms with privileged access to internal infrastructure describe the same profile behind this year’s largest supply chain incidents. How does Terra answer a chief information security officer who calls it their most sensitive third party?

Peled called it the right question and proposed a three-part test: depth of access, blast radius if the vendor is compromised, and degree of autonomy inside the customer environment. On blast radius, he drew a distinction that does real work. Peled described Terra as “a single-customer engagement model, not a shared update channel pushing code into thousands of environments simultaneously.” That is the pattern behind the year’s supply chain failures, and the distinction is fair.

Peled also conceded ground. He said “the agentic era does require a refreshed third-party risk framework,” and that Terra would rather help customers build one than argue about rankings inside the old one.

Deployment options include multi-tenant, single-tenant, and on-premises or air-gapped for regulated environments. Customers can bring their own model.

The Certification Worth Asking About

Peled cited three credentials: SOC 2 Type II, CREST, and ISO 42001. The last one deserves more attention than it usually gets.

SOC 2 attests to controls over data. CREST accredits penetration testing capability. Neither says anything about how a vendor governs the AI doing the work. ISO/IEC 42001:2023 does. Published in December 2023, it is the first international management system standard built specifically for AI. It covers the full lifecycle, from design and development through deployment, monitoring, and decommissioning.

The standard applies to organizations that develop, provide, or use AI systems. That covers Terra and its customers alike. Certification is voluntary, and ISO does not issue it. Independent certification bodies do, and those bodies may hold accreditation from national accreditation authorities.

Why cyber insurance underwriters should care.

Agentic vendors are proliferating faster than any submission form tracks them. ISO 42001 is currently the closest thing to a portable, auditable answer to the question of whether a vendor governs its AI at all. Regulators are already treating international standards as benchmarks, and the European Union’s AI Act conformity assessment procedures reference standards including this one. That gives it weight in UK and EU placements before it gets weight in US ones.

See also  Zywave Details Agentic AI Plan For Insurance Sales Workflows
Why it proves less than it appears to.

This is a management system standard, not a product safety certificate. It certifies that governance processes exist and get audited. It does not certify that any particular agent will behave on any particular engagement. The distinction is the same one that separates ISO 27001 from an actual absence of breaches, and underwriters already know how that story goes.

The useful move is to treat it as a filter rather than a finding. A vendor without it should explain why. A vendor with it should still answer what its agents can do without a human gate.

What Terra Did Not Say

CINI asked the sharpest insurance question first. Continuous validation creates a dated record of every exploitable path a vendor found. If a client is breached through a finding flagged 60 days earlier, does that record support the claim or hand the carrier a denial?

Peled declined to engage. “Coverage outcomes are governed by policy language, and cyber policies vary substantially by carrier, industry, and insured,” he said. He added that “how any specific scenario gets handled will depend on the specific policy, the specific incident, and the specific facts.”

Both statements are true. Neither is an answer. The same pattern held on the outage question, where Peled described the guardrails in detail and never said which policy responds.

This is not evasion unique to Terra. It is the market’s default position, and Cyber Insurance News has documented it repeatedly. Willis found most cyber policies carry no AI exclusion and still fail to respond to several AI loss categories. The Economist Enterprise and Rubrik found nearly all firms running agents had an incident, and few could reconstruct one. The unresolved question of who acted when an agent causes the loss sits underneath all of it.

What Cyber Insurance Underwriters Should Take From This

Terra has built something genuinely useful for risk selection. Continuous validated evidence of exploitable paths beats a self-assessment questionnaire. The dated audit trail is an underwriting asset before it is a claims liability.

It is also both. Every finding logged is a finding someone can later prove the insured knew about. That cuts toward better pricing and toward harder conversations at claim time. Peled will not say which way it cuts, and it is not his job to say. It is the carrier’s.

Ask vendors where the deterministic layer sits. Ask what the agent can do without a human gate. Then ask your broker which policy responds when the answer turns out to be wrong.

See also  SecurityScorecard Achieves StateRAMP Ready Status and Reaffirms FedRAMP Compliance

FAQ – Agentic Pentesting

What did Terra Security announce?

Continuous agentic internal network pentesting, in limited preview with selected design partners as of July 21, 2026. It extends Terra’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says this makes it the first agentic offensive security provider covering all four surfaces.

What is human-on-the-loop, and why does it matter for insurance?

A person supervises the automated system and can intervene, but does not approve every individual action. Human-in-the-loop means a person signs off on each step. The difference matters at claim time, because it shapes who was actually in control when something went wrong.

How does Terra prevent its AI agents from causing damage?

Terra describes three guardrail layers: the foundation model’s own controls, Terra’s platform-level controls that are rule-based rather than AI-based, and customer-configured controls. The company says the rule-based middle layer is the important one, because enforcement does not depend on the same non-deterministic system it governs.

What is ISO 42001, and why does it matter for agentic vendors?

ISO/IEC 42001:2023 is the first international management system standard for artificial intelligence, published in December 2023. It covers the full AI lifecycle and applies to organizations that develop, provide, or use AI systems. Certification is voluntary and issued by independent accredited bodies. It certifies that AI governance processes exist and get audited, not that a given AI system is safe.

Does cyber insurance cover an outage caused by a pentesting agent?

Terra declined to say which policy responds, noting correctly that outcomes depend on specific policy language, incident, and facts. That leaves the allocation between a client’s business interruption cover and a vendor’s errors and omissions cover unresolved. Risk managers should map the scenario with their broker before an engagement begins.

Leave a Comment

×