Evaluation & testing

PyRIT

MIT-licensed Python framework from Microsoft for probing generative AI systems for risk. It is aimed at security engineers running automated adversarial testing campaigns rather than at governance teams, and the repository provides no multi-user controls, evidence retention or reporting workflow of its own.

open_source · generally available · Research snapshot 2026-09-06

Visit the official product source ↗

Where it fits

Evaluation & testing · Agent security & threat detection

Useful conversation with: AI red team engineer, Security engineer.

Ask for a demonstration

Demonstrate an automated PyRIT attack run against my deployed model endpoint and show what artefacts the run leaves behind.

Capabilities and evidence

Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.

Documented by provider

The repository describes PyRIT as an open-source framework built to help security professionals and engineers proactively identify risks in generative AI systems, released under the MIT license.

Limit: The repository landing page does not enumerate attack techniques, scoring, datasets or captured artefacts.

Source s1

Documented by provider

The maintained repository is microsoft/PyRIT, with release v1.1.0 listed as latest on 4 September 2026, while the former Azure/PyRIT repository was archived on 27 March 2026 and is read-only.

Limit: Release listing establishes activity but not feature scope or support commitments.

Source s1 · Source s2

Limitations to discuss

Sources

  1. microsoft/PyRIT: The Python Risk Identification Tool for generative AI · GitHub / Microsoft · official repository
    Access date reported by researcher: 2026-09-06
  2. Python Risk Identification Tool for generative AI (PyRIT) · GitHub / Microsoft · official repository
    Access date reported by researcher: 2026-09-06

Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.

Suggest a correction