Artificial Intelligence

Microsoft Releases Red Teaming Tool for Generative AI

Microsoft releases PyRIT red teaming tool to help identify risks in generative AI through automation.

Microsoft releases PyRIT red teaming tool to help identify risks in generative AI through automation.

Microsoft on Thursday announced the release of PyRIT, an open access red teaming tool designed to help security professionals and ML engineers identify risks in generative AI.

PyRIT, Microsoft says, increases audit efficiency by automating tasks and flagging areas that require further investigation, essentially augmenting manual red teaming.

Red teaming generative AI, the tech giant notes, is different from probing classical AI systems or traditional systems, mainly because it requires identifying both security risks and responsible AI risks, generative AI is more probabilistic, and due to the wide variations in generative AI system architectures.

Generative AI could produce ungrounded or inaccurate content and its output is influenced even by small input variations, and red teaming these systems needs to consider these risks as well.

Furthermore, generative AI systems may vary from stand-alone applications to integrations, and their output may vary greatly as well, Microsoft notes.

PyRIT (Python Risk Identification Toolkit for generative AI), which started in 2022 as a set of scripts for red teaming generative AI, has already proven its efficiency in red teaming various systems, including Copilot.

Advertisement. Scroll to continue reading.

“PyRIT is not a replacement for manual red teaming of generative AI systems. Instead, it augments an AI red teamer’s existing domain expertise and automates the tedious tasks for them. PyRIT shines light on the hot spots of where the risk could be, which the security professional can incisively explore,” Microsoft explains.

The tool provides the user with control over the strategy and execution of the AI red team operation, can generate additional harmful prompts based on the set it was fed with, and changes tactics based on the responses received from the generative AI system.

PyRIT includes support for various generative AI target formulations, can be fed a dynamic prompt template or a static set of malicious prompts, provides two options for scoring the target system’s outputs, supports two styles of attack strategy, and can save intermediate input and output interactions for follow-up analysis.

“PyRIT was created in response to our belief that the sharing of AI red teaming resources across the industry raises all boats. We encourage our peers across the industry to spend time with the toolkit and see how it can be adopted for red teaming your own generative AI application,” Microsoft notes.

PyRIT is available on GitHub.

Related: Google Open Sources AI-Aided Fuzzing Framework

Related: Critical Vulnerabilities Found in Open Source AI/ML Platforms

Related: AI’s Future Could Be Open-Source or Closed. Tech Giants Are Divided as They Lobby Regulators

Related Content

Artificial Intelligence

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Artificial Intelligence

Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

Artificial Intelligence

Corma emerged from stealth with seed funding from Sequoia Capital, Khosla Ventures, and Coatue.

Artificial Intelligence

OpenAI has also announced the expansion of its Daybreak platform to give more organizations access to its AI.

Artificial Intelligence

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. 

Artificial Intelligence

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

Artificial Intelligence

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version