Skip to main content
Fleuret raises €3.5M pre-seed

Continuous AI pentesting: why NIS2 changes the game

Yanis Grigy, CEO2 min read

The problem: NIS2 asks for continuous, the market delivers one-off

NIS2 came into force in October 2024. The directive requires essential and important entities to run regular security tests, proportionate to risk. "Regular" does not mean "once a year". National regulators converge on a quarterly interpretation, sometimes continuous for critical systems.

Traditional pentesting cannot hold that cadence. Two to four weeks for a report, ten to thirty thousand euros per engagement, time slots negotiated months in advance. Multiply by four engagements per year per scope and the bill becomes unsustainable.

Between two pentests, your deployments ship to production unaudited. Three to twelve months of silent exposure. That is exactly the risk NIS2 is trying to reduce.

Agentic AI as an infrastructure answer

An AI agent that reasons like an expert pentester can launch an engagement on demand, in hours instead of weeks. The economics flip: marginal cost of one more test tends toward zero. That is the condition for turning pentest from one-off event into continuous control.

Three concrete implications:

  1. Every production release triggers a pentest. Not a shallow scan, a real intrusion test against the changed perimeter.
  2. Every finding ships with a PoC. Zero false positives, because the agent exploits to prove, not to alert.
  3. The report is audit-ready. CVSS structure, reproducible evidence, prioritized remediation plan. Auditors no longer have to translate.

What it changes for a CISO

Your cybersecurity continuity plan stops being a calendar of engagements. It becomes a posture. You can present NIS2 auditors a history of tests aligned with your deployment cadence, not with a consultancy's availability.

That is what we are building at Fleuret. If you are a European company subject to NIS2 or DORA and this approach resonates with your strategy, let's talk.


Share this postShare on LinkedIn

The Fleuret newsletter

One email a month. Cyber analysis, DORA, NIS2, and what we learn pentesting our customers' apps.

Privacy Settings

This site uses third-party website tracking technologies to provide and continually improve our services, and to display information according to users' interests. I agree and may revoke or change my consent at any time with effect for the future.