AI-driven testing is becoming more focused on evidence, traceability and human oversight, while security vendors are shortening patch cycles and extending continuous validation across increasingly complex enterprise environments.
This week’s roundup includes a new source-to-verdict testing loop from TestMu AI, an expanded crowdsourced testing platform from Testlio, faster Java security updates from Azul and fresh developments from Harness, Tricentis, Cognizant, Onspring and Synack.
OpenQA removes selectors from browser testing
OpenQA has released an open-source automation harness that allows developers and coding agents to write browser tests in plain English rather than maintaining conventional selectors and step definitions.
The agent interprets the requested workflow and determines how to interact with the application, making the tool potentially easier to adapt as interfaces change.
The approach may reduce maintenance, but it also reinforces the need for independent evidence. In regulated environments, QA teams will still need to confirm that an agent followed the intended path and that a passing test represents the correct business outcome.
Cognizant lands five-year insurance deal
Cognizant has signed a five-year partnership with US property and casualty insurer The Andover Companies.
The programme will modernise connections between Andover’s core policy administration platform and its digital services, create an AWS-based enterprise data platform and strengthen its customer and agent portals.
Cognizant will also introduce automated data-quality checks, lineage and classification to support future AI models. The programme underlines the growing overlap between core-system testing, data assurance and AI governance in insurance modernisation.
Testlio rolls out next-generation LeoCore
Testlio has unveiled the latest version of LeoCore, its AI-powered platform for orchestrating software testing.

The platform combines AI-assisted test creation and predictive insights with Testlio’s global community of human testers. Its intelligence layer manages tester selection, testing cycles and results analysis while tracking quality patterns over time.
The company said 22% of critical or high-severity defects identified during first testing cycles involved payment failures.
That makes the combination of automated orchestration and real-world human validation particularly relevant to banks, fintechs and payment providers operating across multiple devices, markets and payment methods.
Azul accelerates Java security patching
Azul will begin issuing monthly Critical Security Patch Updates for supported Java Long-Term Support versions from next week.
The company said the traditional quarterly cadence can leave serious vulnerabilities unpatched for weeks. The new security-only updates will cover Java 8, 11, 17, 21 and 25, as well as Java 26 and the older Java 6 and 7 versions supported by Azul.
The faster schedule will also increase the need for efficient regression testing. Banks running large Java estates must be able to validate and deploy security fixes quickly without destabilising trading, payments or other mission-critical systems.
TestMu AI builds evidence into release decisions
TestMu AI has introduced a source-to-verdict loop within Kane CLI, designed to take a product requirement through test design, browser execution and coverage analysis before returning a ship-or-hold verdict.

The tool can ingest requirements from sources including Jira tickets, product documents, Figma designs and demonstration videos. Each run produces an open evidence pack containing execution data, coverage information and failure analysis.
For financial firms, the emphasis on portable, auditable proof addresses a growing concern around agentic testing: a passing result is only useful if teams can establish what was tested, how it ran and which requirement it actually validated.
Harness and Kong target agent security
Harness and Kong have expanded their strategic partnership to address security risks created by AI architectures, autonomous agents and Model Context Protocol deployments.
The companies are bringing API and agent security more closely into governed software delivery workflows, with the aim of improving visibility and control as agents interact with enterprise services.
For financial institutions, this extends testing beyond whether an agent produces the expected answer. Teams increasingly need to validate which tools an agent can access, how it invokes APIs and whether those interactions remain within established security and governance boundaries.
Onspring launches agentic GRC capabilities
Onspring has expanded its GRC platform with AI agents that can automate workflows and make rule-based decisions within controls defined by administrators.
The agents can review newly attached documents, identify possible control gaps, generate third-party follow-ups and analyse records across audits, risk assessments and incident logs. Actions remain visible and auditable within the platform.
For banking QA and resilience teams, the launch highlights an important principle for agentic systems: automation should operate within testable rules, with clear records of what the agent did and why.
Synack expands access to continuous security testing

Synack’s AI and human-led penetration-testing services are now available through Carahsoft’s programme on AWS Marketplace.
Its platform combines the Sara autonomous red agent with human security researchers to map attack surfaces, test applications and APIs, and validate whether identified vulnerabilities are genuinely exploitable.
Although the arrangement initially targets the US public sector, the model is relevant to financial institutions facing similar resilience pressures. It reflects the wider shift from periodic penetration tests towards continuous security validation supported by both AI and expert review.
Tricentis takes top automated quality position
Tricentis has moved into the leading revenue position in IDC’s worldwide automated software quality market rankings for 2025.
The company captured 6.9% of a market valued at $6.3 billion, according to the research. IDC defines the segment as covering test automation, quality management, performance testing, code analysis and emerging AI-assurance capabilities.
The figures provide further evidence that testing is expanding beyond traditional automation. AI assurance and agentic quality engineering are becoming established enterprise spending categories as firms look for greater control over rapidly increasing volumes of software.
THIS SEPTEMBER IN LONDON



REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Goldman puts AI coding to the test
- How to test AI models that banks do not control
- OpenAI, Filigran and SunTec: the latest vendor and product news
- Sygnum: Testing AI is ‘a measurement problem’
- Banks’ ‘code for all’ push raises testing risks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



