Parabellum named a Founding Signatory of the CREST AI Charter
Parabellum has become a founding signatory of the CREST International AI Charter, a public commitment to the responsible, transparent and accountable use of artificial intelligence across cybersecurity services. We are proud to stand among the first cohort of CREST members worldwide to put our name alongside it.
The Charter is the work of CREST, the international not-for-profit that accredits cybersecurity providers and sets professional standards across the industry. Its founding cohort spans more than 70 organisations across Europe, North America, the Middle East and the Asia-Pacific, representing roughly one in ten CREST members. For a firm already accredited by CREST, and with a Parabellum director recently elected to the CREST Australasia Council, signing the Charter was a natural extension of standards we already hold ourselves to.
Why this matters now
AI is no longer on the edge of cybersecurity. It sits inside the work. CREST's own research found that 69% of providers now use AI somewhere in their penetration testing workflows, and that 76% have increased that use over the past year, most commonly in reconnaissance, analysis and reporting.
That shift brings real advantages: faster triage, broader coverage, sharper prioritisation of the findings that actually matter. But cybersecurity is an industry built on assurance, and capability without accountability is a liability. When AI helps shape a finding, a risk score or a recommendation, clients are entitled to know where it was involved, how it was governed, and who remains answerable for the outcome.
The question was never whether to use AI. It is how to use it without diluting the trust, transparency and human judgement that clients are paying for. That is the gap the Charter sets out to close.
The Charter and our commitments
Signing the Charter means publicly supporting CREST's nine AI Principles, a shared framework for how AI is governed, deployed and overseen in security work. In practice, they cover:
- Accountability and governance: defining the scope and purpose of AI-enabled activity, with oversight and controls proportionate to the risk.
- Transparency of use: telling clients where AI plays a part in their service, including its benefits, limitations and risks.
- Documentation and assurance: keeping AI use traceable, reviewable and recorded for assurance purposes.
- Boundaries and control: ensuring competent people retain oversight of AI-enabled activity, reviewing outputs and challenging decisions.
- Data, sovereignty and client control: handling client data within agreed boundaries and respecting sovereignty requirements.
- Security and confidentiality: protecting the confidentiality and integrity of information processed by AI tooling.
- Secure development of AI tooling: building and maintaining AI capabilities securely.
- Supply chain assurance: extending the same expectations to third-party and vendor AI solutions.
- Resilience and business continuity: ensuring AI-enabled services remain reliable and recoverable.
For Parabellum, none of this changes the fundamentals of how we work. Our engagements have always been led by cleared, certified specialists who validate findings, demonstrate exploitability with evidence, and translate technical risk into decisions a board can act on. Where AI supports that work, it supports our expertsit does not replace the judgement our clients rely on. A qualified human stays in the loop, and a person remains accountable for the outcome.
What it means for our clients
Whether you engage us for web application, hardware or OT/SCADA/ICS penetration testing, incident response, red teaming, security architecture review or governance and framework development, the Charter is a straightforward signal:
- Where we use AI, we will be open about it.
- We will govern it, document it, and keep it inside the boundaries we have agreed with you.
- Your data is handled with the sovereignty and confidentiality expectations that regulated Australian organisations require.
- A qualified specialist remains accountable for every finding and recommendation you receive.
For the sectors we work closest with, critical infrastructure, operational technology, and regulated industries where a wrong call carries real-world consequences,that discipline is not a nice-to-have. It is the baseline.
A commitment to the standard, not just the technology
Adopting AI responsibly is an ongoing discipline, not a one-time tick and flick. Alongside the Charter, CREST is developing standards for AI security and the use of AI in cybersecurity services, convening working groups and publishing independent research to support trusted adoption worldwide. As a founding signatory, and through our seat on the CREST Australasia Council, Parabellum intends to be an active part of shaping that work, not just a name on the list.
AI will keep changing how cybersecurity gets done. Our commitment is to make sure it never changes the standard of assurance, transparency and human expertise our clients depend on.

.png)

.png)
.png)
.png)
.jpg)