Aikido Security Launches On-Premise AI Pentesting with Acquisition of Milou
Key Takeaways
- ▸Aikido Security launches the Aikido Machine, an on-premise AI pentesting server that keeps all code and prompts within the customer's network
- ▸The product addresses regulatory requirements for highly regulated industries (banking, government, defense, healthcare) that cannot send code to external cloud services
- ▸Aikido Security acquires Milou, a Belgium-based offensive security firm, to strengthen AI pentesting expertise and local hardware optimization
Summary
Aikido Security has launched the Aikido Machine, an on-premises server that delivers AI pentesting and code analysis capabilities entirely within a client's network, ensuring no source code, repositories, or prompts ever leave the infrastructure. This product directly addresses the needs of highly regulated industries—including banking, government agencies, defense contractors, and healthcare providers—that face regulatory barriers against sending proprietary code to external cloud services. The company simultaneously announced its acquisition of Milou, a Belgium-based offensive security firm founded by experienced pentesters Tiburce Gridello and Selim Decamps, whose expertise in automating security workflows and local hardware optimization strengthened the development of the Aikido Machine.
The launch responds to escalating AI-driven cyber threats and regulatory pressure. The European Central Bank recently mandated 110 banks develop action plans against AI-driven attacks within four months, while the European Systemic Risk Board elevated systemic cyber risk to "severe," citing frontier AI models as a paradigm shift for cybersecurity. Traditional defenses are struggling: 51% of CISOs and CTOs report that multi-step vulnerabilities and logic flaws are missed routinely. The Aikido Machine addresses these gaps by enabling continuous, AI-powered pentesting with local GPU inference, eliminating token-based fees and enabling 24/7 security testing within air-gapped networks.
- Continuous pentesting model eliminates per-test fees and token constraints, enabling always-on security scanning
- Designed to counter AI-driven cyber threats and address regulatory pressure from bodies like the ECB and European Systemic Risk Board
Editorial Opinion
The Aikido Machine represents a pragmatic recognition that AI security tooling must adapt to regulatory realities. By moving inference entirely on-premise rather than forcing a false choice between security best practices and regulatory compliance, Aikido captures a significant market segment that competitors have overlooked. The acquisition of Milou signals serious intent to compete on exploit quality, not just model performance—a wise positioning as enterprises increasingly demand proof of finding real vulnerabilities, not just theoretical ones.



