Back to glossaryCyber

Red teaming

Attack-simulation exercise conducted by a mandated team to probe the defenses of an IT system or AI model by emulating the behavior of a real adversary.

Definition

Red teaming is an offensive evaluation practice in which an independent team, the red team, is engaged to attack a target system under rules of engagement defined by contract. Originating in military jargon and Cold War war-gaming exercises, the concept was adopted by information security before being adapted to the evaluation of AI models. In cybersecurity, the red team seeks to compromise production systems by combining technical intrusion, social engineering and sometimes physical exploitation. It differs from conventional penetration testing through its strategic dimension: the objective is not to enumerate vulnerabilities but to demonstrate the real-world impact of a compromise on the organization's mission. The blue team, responsible for defense, attempts to detect and contain the simulated attack; an exercise combining both is called a purple team. In AI, red teaming refers to the systematic effort to elicit harmful, biased or instruction-violating outputs from a model in order to identify its weaknesses before deployment. The EU AI Act and the voluntary commitments signed by major model providers make red teaming an expected practice before market release for high-risk systems. For the insurer, documented red-team exercises constitute evidence of due diligence that can influence the pricing of a cyber policy or the professional liability cover of an AI vendor.

Example

A cyber insurer, at renewal of a policy covering an AI-powered medical platform, requires a red-teaming report produced within the previous twelve months. The exercise, conducted by an external team, identified a prompt-injection vector capable of bypassing clinical guardrails. Renewal is granted subject to a raised deductible and a contractualized remediation plan.

Related terms
Also known as

équipe rouge, red team, test adversarial, adversarial testing, exercice de simulation d'attaque