The three layers of real AI testing in 2026

The three layers of real AI testing in 2026

Cyril Treacy

COO and Co-Founder

This post explains what AI testing actually has to cover under the EU AI Act in 2026, why most platforms stop at Layer 1 or Layer 2, and what the third layer adds that regulators are now reading Article 9 and Article 72 against.

This post explains what AI testing actually has to cover under the EU AI Act in 2026, why most platforms stop at Layer 1 or Layer 2, and what the third layer adds that regulators are now reading Article 9 and Article 72 against.

Key Takeaways

  • Real AI testing in 2026 is three layers: input validators, advanced jailbreak techniques, and a live vulnerability database that tracks the attacks discovered after the system shipped.

  • Most platforms calling themselves AI testing tools cover Layer 1 only, a smaller group adds Layer 2, and almost none operate a Layer 3.

  • Layer 1 is 65 input validators across base, RAG, agentic, and MCP families, running as ML classifiers on CPU in milliseconds, with the platform auto-surfacing the top five for any given use case.

  • Layer 2 is 84 known jailbreak techniques, with a Jailbreaking Agent picking which to deploy based on the scenario the user describes.

  • Layer 3 is a live vulnerability database, continuously updated with newly published LLM vulnerabilities including reversal of alignment decisions under pressure and the poetry jailbreak.

  • The regulator's real question is not "did you test your AI" but "did you test it against the vulnerabilities that existed when you deployed", and Layer 3 is the only honest answer.

Key Takeaways

  • Real AI testing in 2026 is three layers: input validators, advanced jailbreak techniques, and a live vulnerability database that tracks the attacks discovered after the system shipped.

  • Most platforms calling themselves AI testing tools cover Layer 1 only, a smaller group adds Layer 2, and almost none operate a Layer 3.

  • Layer 1 is 65 input validators across base, RAG, agentic, and MCP families, running as ML classifiers on CPU in milliseconds, with the platform auto-surfacing the top five for any given use case.

  • Layer 2 is 84 known jailbreak techniques, with a Jailbreaking Agent picking which to deploy based on the scenario the user describes.

  • Layer 3 is a live vulnerability database, continuously updated with newly published LLM vulnerabilities including reversal of alignment decisions under pressure and the poetry jailbreak.

  • The regulator's real question is not "did you test your AI" but "did you test it against the vulnerabilities that existed when you deployed", and Layer 3 is the only honest answer.

Most AI testing in 2026 still tests the wrong thing

When the category was new, Layer 1 was the state of the art: run adversarial prompts, score responses, ship a report. Most platforms still do that.

Article 9 of the EU AI Act requires continuous risk management including pre-deployment testing against foreseeable misuse. Article 15 requires demonstrable robustness. Article 72 requires post-market monitoring against new vulnerabilities.

A regulator wants to see what was tested, what attacks were used, and what new vulnerabilities the buyer tested between deployment and audit. A static library cannot answer the third.

Layer 1: input validators, 65 of them, running in milliseconds

Layer 1 is the direct adversarial check: does this LLM, on this prompt, behave the way policy says it should? Disseqt runs 65 validators across four families covering base model risks, RAG pipelines, agentic workflows, and Model Context Protocol surfaces.

Every validator is a small ML classifier tuned to one failure mode, running on CPU in milliseconds. The same infrastructure does pre-production testing and runtime enforcement, keeping the assurance record continuous.

The 65 are a library, not a checklist. The platform auto-surfaces the top five for the scenario, so the team shipping does not need to be an AI safety expert.

Skip Layer 1 and the Article 9 file has no foundation. But Layer 1 only tests normal prompts, not real jailbreaks.

Layer 2: advanced jailbreaking, 84 techniques, picked by an agent

Layer 2 asks whether the LLM holds up against the jailbreaks attackers use in the wild. Disseqt's library covers 84 known techniques across role-play, encoding, multi-turn, recursive, and adversarial-suffix attacks plus newer agentic patterns.

Running 84 manually is not serious. The Jailbreaking Agent reads the scenario (agent type, data touched, tools called, user population) and picks which to deploy. The user describes the agent in plain English. The platform picks the attacks.

Skip Layer 2 and the Article 15 robustness claim collapses on first contact with a red team. Layer 2 is still a snapshot. Yesterday's attacks are not in it.

Layer 3: a live vulnerability database, and the poetry jailbreak

The poetry jailbreak is the one I show in demos. Four generated poems, encoding a request the LLM has been trained to refuse, fired at the model as creative writing. The model parses them as poetry and complies. That technique was not on any testing library a year ago. It is on ours, because Layer 3 pulled it in the day it published.

Layer 3 is the live vulnerability database. New vulnerabilities from arXiv, researcher disclosures, provider advisories, and red team write-ups get pulled in continuously. A vulnerability dated the ninth of March is testable on the tenth.

The platform also catches reversal of alignment decisions under pressure, where the LLM refuses then capitulates after the user reframes the request as urgent. In every customer's test run within a day of publication.

Almost no competitor has this layer. Most ship a quarterly release and call it "updated." The regulator's real question, the one Article 72 is built around, is not "did you test your AI?" It is: "did you test it against the vulnerabilities that existed when you deployed?" Only a live database can answer that.

Bottom Line

AI testing in 2026 is three layers because the threat model is three layers. Layer 1 catches adversarial prompts. Layer 2 catches today's jailbreaks. Layer 3 catches the vulnerabilities that did not exist at ship but exist by audit.

Disseqt runs all three on one ML and CPU spine across Test & Detect, Protect & Enforce, and Prove & Comply.

Layer 1 alone is the floor. Plus Layer 2 is most of today's threat model. Without Layer 3, Article 72 has a gap that grows every week.

Explore the Disseqt platform

FAQs

01

What is Layer 3 in AI testing and why does it matter?

Layer 3 is a live vulnerability database that pulls in newly published LLM vulnerabilities continuously, so testing covers attacks discovered after the platform shipped. Article 72 requires post-market monitoring against emerging vulnerabilities, and a static library cannot evidence that.

02

How is advanced jailbreak testing different from input validation?

Input validators run ML classifiers against failure modes like bias, prompt injection, or PII leakage on normal prompts. Jailbreak testing runs known attack techniques like role-play overrides and recursive prompt chains designed to bypass safety training. Disseqt covers 65 validators and 84 techniques.

03

Why does Disseqt's testing platform run on CPU and ML rather than LLMs?

LLM-as-judge inherits the same cost, latency, and energy footprint as the model it tests, which breaks at agentic scale. ML classifiers on CPU run in milliseconds with around 98% less CO2 and 99% less water. That makes the infrastructure usable pre-deployment and at runtime.

04

What does the poetry jailbreak actually do?

It generates four poems that encode a request the LLM has been trained to refuse, and fires them at the model as creative writing prompts. The model parses them as poetry rather than as the underlying request, and complies. Layer 3 picked it up the day it was published.

AUTHOR

Cyril Treacy

COO and Co-Founder

Cyril is Co-Founder and COO at Disseqt, leading go-to-market, partnerships, and customer success. He brings 20+ years of enterprise sales, pre-sales leadership, and scaling expertise from Salesforce and the Irish startup ecosystem.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.