AI-Driven Mobile Application Penetration Testing in the European Financial Sector — A Control-Based Evaluation of Djini.ai

Can an AI-driven penetration testing tool meet the regulatory requirements of the European financial sector? This thesis develops a 29-control framework and applies it to a representative tool — providing the first systematic view of a new tool category.

Gökpinar, Miran, 2026

Type of Thesis Bachelor Thesis
Client Mobile Hacking Lab
Supervisor Grimberg, Frank
Views: 2
The European financial sector faces two simultaneous developments. New EU regulations (DORA in force since January 2025, EU AI Act phasing in through 2026–2027, Cyber Resilience Act applying from December 2027) tighten the requirements for cybersecurity testing. At the same time, banks increasingly adopt AI-driven penetration testing tools. However, existing evaluation frameworks were written for human testers. Whether and how they apply to AI-driven tools has not been systematically examined. This gap creates regulatory uncertainty for both tool providers and banks.
The thesis follows a Design Science Research approach. From six regulatory and industry instruments (DORA, GDPR, AI Act, CRA, NIST SP 800-115, OWASP MASVS/MASTG), 125 atomic requirements were extracted and consolidated in a two-step process into 29 controls. These were validated with two senior cybersecurity practitioners from a Big Four consulting firm and applied as the evaluation instrument for a representative AI-driven mobile pen testing tool. The evaluation basis included a 66-page sample penetration testing report and the tool's deployment architecture.
The evaluated tool receives "Fully Met" or "Largely Met" ratings on 11 of the 29 controls — the technical capability is substantial. 16 controls receive "Partially Met", two "Not Met". The central insight: the limiting factor is not technical capability but the formal compliance perimeter — standardised documentation, external assurance, notification processes. These gaps can be closed through documentation and process work, not through new product features.Two reusable artefacts emerge from the analysis: the 29-control framework and a six-class gap typology that distinguishes provider-remediable gaps (Classes A–D) from deployer-side obligations (Classes E–F). Concrete recommendations follow for both sides: seven for the tool provider (including an independent third-party pen test of the platform, standardised contractual clauses, and a CRA notification process) and six for the deploying bank. The benefit for the provider is a structured roadmap that prioritises the measures most directly accelerating market entry into regulated European financial institutions.
Studyprogram: Wirtschaftsinformatik (Bachelor)
Keywords AI-Driven Penetration Testing, EU Financial Sector Compliance, DORA, EU Artificial Intelligence Act, Cyber Resilience Act, GDPR, NIST, IT-Audit
Confidentiality: vertraulich
Type of Thesis
Bachelor Thesis
Client
Mobile Hacking Lab, Leuuwarden, Netherlands
Authors
Gökpinar, Miran
Supervisor
Grimberg, Frank
Publication Year
2026
Thesis Language
English
Confidentiality
Confidential
Studyprogram
Wirtschaftsinformatik (Bachelor)
Location
Olten
Keywords
AI-Driven Penetration Testing, EU Financial Sector Compliance, DORA, EU Artificial Intelligence Act, Cyber Resilience Act, GDPR, NIST, IT-Audit