AI agents now act on delegated authority. We test whether they can be made to exceed it.

ENTROPY is an AI red-teaming company. We attack AI agents and LLM applications the way an adversary would, through their inputs, tools and data, and report only what we can demonstrate.

  1. 1. Scope

    Every engagement starts from a written scope: the system, the access we are given, and the outcomes that must never occur.

  2. 2. Attack

    We search for paths from untrusted input to one of those outcomes, across prompts, retrieved content, tools and permissions.

  3. 3. Evidence

    A finding is reported with the record that it happened: the trace, the log entry, the resulting state. Not a model’s opinion that it might have.

  • Oxford University Innovation, Incubator Phase 1
  • CODE University of Applied Sciences, Berlin

Scope an assessment

We take on a small number of engagements at a time. Tell us about the system you are deploying.

Get in touch