AI and LLM Security Testing in Your VAPT RFP: What to Specify in India in 2026

October 2026 Security & VAPT VAPT & Penetration Testing Security, VAPT, India

Why the RFP Needs to Say It Out Loud

A traditional VAPT scope lists IP ranges, URLs and applications. An AI-enabled application adds a layer that scope language was never written for: a language model that takes untrusted text as input, may be connected to internal documents, and in many deployments can call tools or APIs on a user's behalf. If the RFP only says "web application penetration test", a bidder can deliver a perfectly competent test of the login page and API layer and never touch the chatbot or copilot sitting on top of them.

Security teams are increasingly asking for this to be written into the scope explicitly, rather than left to the bidder's interpretation. The practical benefit is comparability: when every bidder prices the same AI-specific scope, you can compare their quotes and their methodology instead of comparing a narrow scope against a broad one.

The Three Risk Areas Worth Naming

  • Prompt injection. Can crafted input, whether typed by a user or hidden in a document, web page or email the model reads, override the application's instructions? Ask bidders to test both direct injection and indirect injection through content the model retrieves.
  • Data leakage. Can the model be coaxed into revealing its system prompt, other users' data, or documents it was connected to for retrieval but the requesting user should not see? Scope should cover access-control behaviour of any retrieval layer, not just the model's replies.
  • Tool and agent abuse. If the application can send email, query a database, call an internal API or take actions, can an attacker steer it into doing so? This is the area where an AI feature stops being a content risk and becomes a path into your systems, so it deserves its own line in the scope.

The OWASP Top 10 for LLM Applications is a sensible shared vocabulary to reference in the RFP, because most credible bidders already map their test cases to it. Referencing a public framework also makes the report easier to audit later. Our own overview of LLM application penetration testing in India goes deeper on the technical side.

What to Ask Bidders

  • Which model and architecture decisions are in scope? A hosted third-party model, a self-hosted one and a retrieval pipeline over your documents each carry different risks. Say which you have, and ask how the test approach changes.
  • Who owns testing of the model provider's side? Most providers restrict what you may test against their infrastructure. Ask the bidder to state clearly what is out of bounds, so nobody assumes it was covered.
  • How are findings rated? Prompt-injection results are less binary than a classic SQL injection. Ask how the bidder scores severity and how they separate a reproducible exploit from a one-off odd response.
  • What does retesting look like? Model behaviour is probabilistic, so a fix often needs more than a single re-run. Ask how many attempts a retest uses before a finding is closed.
  • Who on the bidder's team has done this before? Ask for named testers and a sanitised sample report, not a general statement that the firm covers AI.

Common Gaps in AI Testing Scope

  • Testing the model in isolation. The riskiest behaviour usually emerges from the model combined with your data connectors and tools. Test the integrated application, not a standalone model endpoint.
  • Excluding the internal copilot. Teams scope the customer-facing chatbot and forget the employee assistant that can search HR, finance or source-code repositories. The impact of a leak there is often larger.
  • One-time testing of a changing system. Prompts, models and connected tools change often. Agree up front when a change triggers a retest, rather than treating the assessment as a permanent certificate.
  • No data-handling terms. Testers will send adversarial content and may see real data in responses. The RFP should state how test data, transcripts and evidence are stored, who can access them and when they are deleted.

eNeoteric's VAPT engagements and security services can scope AI and LLM testing alongside your conventional application and network assessment. If you are drafting an RFP, or want a second opinion on the AI clauses in one you have received, email [email protected] or talk to our team.

Explore all ← Back to Insights

View all Insights