Google has shared details of an internal project called PageBreak, an AI agent that checks web applications for vulnerabilities. Its job isn’t to produce a long list of suspected issues but to confirm whether a problem actually exists.
Why this approach is needed
Automated scanners and AI assistants can find plenty of potential bugs, but many of those signals turn out to be false positives. Security teams spend time checking hypotheses instead of fixing the vulnerabilities that are truly dangerous.
PageBreak is built around verifying evidence. According to Google’s description, the agent explores the application on its own and tries to reproduce an attack scenario. This helps separate a theoretical issue from one that actually works.
What the internal test showed
Google ran the system on its own web applications. In the published example, the agent found only two XSS vulnerabilities among a large number of tested applications, and both were tied to internal or debug components that lacked protection.
That doesn’t mean PageBreak can be installed on any website like an ordinary antivirus. For now, this is an internal Google tool and an approach to testing, not a ready-made service for website owners.
Why this news matters for developers
AI in security is only useful when it reduces manual work rather than creating a new queue of questionable reports. Tools that can confirm a risk could make code reviews faster and clearer.
At the same time, automation doesn’t replace human review. Access control, logging, fixes and the decision to release an update remain the responsibility of the team that maintains the product.














