Short version: AI is a tool, not the practitioner. We use it to assist parts of how we work — never to make security judgements, interpret findings, advise clients, or author deliverables.

Where we stand

We use AI in parts of how we work, and we're not going to pretend otherwise, or dress it up as more transformative than it is. It helps us move faster on the mechanical parts of the job; it does not do the job.

What AI doesn't do: make security judgements, interpret findings, advise clients, or substitute for practitioner reasoning. Those require domain knowledge, accountability, and contextual judgement we don't outsource to a model.

Where we use it

Every use below is human-led and independently reviewed:

  • Writing and documentation
  • Development assistance (code and tooling) which is always reviewed before it ships
  • Research. Verified independently

Where we don't

These are hard lines, regardless of convenience:

  • Client data sent to external AI platforms
  • Security findings interpreted by AI
  • Client deliverables authored by AI
  • Engagement decisions delegated to a model
  • Generated code shipped without review

Our commitments to clients

  • Transparency about when and where AI is involved
  • Human ownership of client deliverables
  • Client data stays within the engagement environment; only a licence heartbeat leaves
  • Practitioner-grade scepticism applied to all AI outputs
  • This statement updated if our position materially changes
Last updated: September 2026  ·  info@breaklinesecurity.com