Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Scan for Good: Wiz's AI Pentester Helps Hospitals and Rail

Scan for Good: Wiz's AI Pentester Helps Hospitals and Rail

Wiz and Google DeepMind's Scan for Good offers AI-powered security scans to hospitals, transit and nonprofits, with every finding checked by humans first.

Kai Aegis
Kai Aegis★Sep 24, 2026★3 min read

Some of the organizations people rely on most, such as hospitals, transit operators and small local governments, often have the least money for security testing. A new program from Wiz and Google DeepMind aims to close that gap with AI. Announced on September 24, 2026, Scan for Good points Wiz's AI penetration testing agent at the public-facing systems of eligible organizations, then has human researchers confirm every finding before it is privately disclosed.

  • The tool: Wiz's Red Agent, an AI pentester running on Google DeepMind's Gemini 3.8 Flash Cyber model
  • Who it serves: hospitals, transit, municipalities, critical infrastructure, nonprofits and under-resourced organizations
  • Permission first: scans run only with explicit consent, via an application or an existing disclosure policy
  • Human review: researchers validate each finding before private disclosure

How Does Scan for Good Work?

The Red Agent examines an organization's public-facing websites, APIs and applications the way an outside tester would, looking for exposed data, weak access controls and misconfigurations. The AI does the broad, tireless exploration; Wiz's human researchers then check each result so organizations receive confirmed issues rather than a pile of noise.

Consent is central. Wiz says testing only happens with explicit permission, either when an organization applies to the program or when it already publishes a bug bounty or vulnerability disclosure policy that invites research. The Register reports that the program is free to participating organizations.

What Has Scan for Good Already Fixed?

Wiz shared examples of issues found and privately reported during its early work, which show why this kind of help matters:

  • A rail operator: a production database exposing administrative sessions
  • A municipality: an exposure affecting records for around 5,000 elderly residents
  • A hospital: missing access controls on a public-facing system
  • A national archive: an exposed administrative key covering 8.8 million files
  • Snowflake: a GitHub Actions issue that was patched the same day it was reported

Each of these is exactly the kind of quiet misconfiguration that a well-funded security team would catch on a routine test, and that a small organization might never find on its own.

Why AI Pentesting Changes the Economics

Traditional penetration tests are priced per engagement, which puts them out of reach for many public-service groups. An AI agent that can cover the initial exploration changes the cost curve, and keeping humans in the loop protects the quality of the results. Gemini 3.8 Flash Cyber has already shown its value on the defensive side, as we covered in how it fixed 2.6x more Chrome bugs.

The Bigger Trend in Defensive AI

Scan for Good joins a growing wave of programs putting frontier AI to work for defenders, including OpenAI's $1 billion push for frontline cyber defenders. The common thread is capacity: AI does the high-volume searching, and scarce human experts spend their time on validation and fixes. For more on tools that help defenders, see our AI security coverage.

Sources: Wiz — September 24, 2026; The Register — September 24, 2026; Nextgov — September 2026.

More Ai Security Stories