AI-Driven Mobile Application Penetration Testing in the European Financial Sector — A Control-Based Evaluation of Djini.ai
Can an AI-driven penetration testing tool meet the regulatory requirements of the European financial sector? This thesis develops a 29-control framework and applies it to a representative tool — providing the first systematic view of a new tool category.
Gökpinar, Miran, 2026
Art der Arbeit Bachelor Thesis
Auftraggebende Mobile Hacking Lab
Betreuende Dozierende Grimberg, Frank
Views: 1
The European financial sector faces two simultaneous developments. New EU regulations (DORA in force since January 2025, EU AI Act phasing in through 2026–2027, Cyber Resilience Act applying from December 2027) tighten the requirements for cybersecurity testing. At the same time, banks increasingly adopt AI-driven penetration testing tools. However, existing evaluation frameworks were written for human testers. Whether and how they apply to AI-driven tools has not been systematically examined. This gap creates regulatory uncertainty for both tool providers and banks.
The thesis follows a Design Science Research approach. From six regulatory and industry instruments (DORA, GDPR, AI Act, CRA, NIST SP 800-115, OWASP MASVS/MASTG), 125 atomic requirements were extracted and consolidated in a two-step process into 29 controls. These were validated with two senior cybersecurity practitioners from a Big Four consulting firm and applied as the evaluation instrument for a representative AI-driven mobile pen testing tool. The evaluation basis included a 66-page sample penetration testing report and the tool's deployment architecture.
The evaluated tool receives "Fully Met" or "Largely Met" ratings on 11 of the 29 controls — the technical capability is substantial. 16 controls receive "Partially Met", two "Not Met". The central insight: the limiting factor is not technical capability but the formal compliance perimeter — standardised documentation, external assurance, notification processes. These gaps can be closed through documentation and process work, not through new product features.Two reusable artefacts emerge from the analysis: the 29-control framework and a six-class gap typology that distinguishes provider-remediable gaps (Classes A–D) from deployer-side obligations (Classes E–F). Concrete recommendations follow for both sides: seven for the tool provider (including an independent third-party pen test of the platform, standardised contractual clauses, and a CRA notification process) and six for the deploying bank. The benefit for the provider is a structured roadmap that prioritises the measures most directly accelerating market entry into regulated European financial institutions.
Studiengang: Wirtschaftsinformatik (Bachelor)
Keywords AI-Driven Penetration Testing, EU Financial Sector Compliance, DORA, EU Artificial Intelligence Act, Cyber Resilience Act, GDPR, NIST, IT-Audit
Vertraulichkeit: vertraulich