BEST PRACTICES · AI & SECURITY
Your security team has questions about AI. This guide answers them in plain words, in about five minutes.
Katalon Studio 11.5 · Katalon True Platform · September 2026
1. Is this you?
✓ You are about to roll out Katalon Studio, and security must sign off first.
✓ Someone asked: “Does this tool send our data to ChatGPT?”
✓ Your company has an AI policy, and you need to show you follow it.
✓ You like the AI features, but want them on your terms.
2. The short answer
If you only read one part, read this.
| Your admin can switch Katalon AI off for the whole account in one click. | Use Katalon’s AI, your company’s own AI provider, or none at all. | Recording, running tests and reports all work the same with AI off. |
3. What does AI actually do in Katalon Studio?
AI is a helper, not the engine. It only works when a user asks it to, or when a team turns a feature on.
| AI FEATURE | HOW IT HELPS | WHAT IT LOOKS AT |
|---|---|---|
| AI Assistant (chat) | Writes, explains and fixes tests when you ask | Your question, the test you have open, files you attach |
| Web Recording Agent | Builds a test from a sentence like “book an appointment” | The web page it is testing |
| AI self-healing | Finds a button again after the page changes | The page and a screenshot, at the failing step |
| AI failure analysis | Explains in plain words why a test failed | The error message and log |
| AI keywords [LLM] | Checks text or files that change every time | The text or file the test gives it |
4. Where does the data go?
Think of it as two roads. Your admin decides which roads are open.
Did you know? On Road 2, your data goes directly to the AI provider your company chose. It never passes through Katalon’s servers.
5. Who holds the switch?
There are three switches. The first one does most of the work.
1 · Your Katalon admin — one switch for everyone
In Katalon True Platform, go to Account Settings → System → Configurations → AI Services. Turn Enable AI Features off, and Katalon AI is off for every user. It is on by default, so check it early.
The admin switch in True Platform. Shown here switched on.
2 · Each user’s Studio — follows the admin
In Preferences → Katalon → AI Configuration, users see what the admin allows. Admin settings appear locked with “managed by Admin”. A user can also pick None to hide AI on their machine.
3 · Your IT team — keys and network
Road 2 needs an AI key. If your policy says no AI, simply don’t hand out AI keys. For extra peace of mind, your network team can block AI provider websites.
6. Pick your setup
Most teams fit one of these three.
SETUP A “No AI, please.”
Do: Admin turns off Enable AI Features. IT doesn’t issue AI keys. Done.
SETUP B “AI is fine, but only through our own provider.”
Do: Admin keeps AI on and picks Use your organization’s AI Key, then adds your provider (for example Azure OpenAI or AWS Bedrock). Every AI request goes only there — Katalon never falls back to its own AI.
SETUP C “We’re happy to use Katalon AI.”
Do: Nothing to change. With a Katalon Studio Enterprise license, Katalon AI works out of the box.
7. What still works with AI off
Everything your team uses to test every day:
✓ Recording, Spy, and writing tests by hand or in script.
✓ Running tests in Studio and in CI with Katalon Runtime Engine.
✓ Keywords, test data, reports, and sending results to True Platform.
✓ Standard self-healing, which finds broken locators without AI.
8. Good to know
Five quick facts security teams often ask about.
✓ One switch, everywhere. The admin switch turns off Katalon AI in Studio, in Runtime Engine runs in your CI pipeline, and in True Platform. Runtime Engine just notes it in the log — your tests still run.
✓ Offline or License Server? Katalon AI is not available in these setups at all.
✓ Chat history stays on the user’s computer. AI Assistant conversations are saved locally. They are not synced to the cloud or shared with the team.
✓ You can see which tests AI helped create. AI-generated tests get a tag and show in purple in Test Explorer — handy for audits.
✓ Not every connection is AI. Studio still talks to Katalon to sign in, check your license and upload test results. That traffic has nothing to do with AI.
9. How to check it’s off
Three quick checks on one machine. Take screenshots for your review file.
-
Open the AI Assistant in Studio. It should say no AI is available.
-
Run a normal test suite. It should run and create reports as usual.
-
Ask your network team to check their logs during the run. No traffic to AI providers should appear.
10. Myths, cleared up
| MYTH | “Katalon Studio quietly sends our tests to AI.” |
|---|---|
| FACT | AI features work only when they are switched on and used. Your admin decides if they are on. |
| MYTH | “Turn off AI and self-healing stops working.” |
| FACT | Standard self-healing keeps working. Only the AI extra is off. |
| MYTH | “The admin switch blocks every possible AI.” |
| FACT | It switches off Katalon AI. AI with a personal key needs that key — so key control stays with your IT team. |
11. Learn more
| TOPIC | KATALON DOCS |
|---|---|
| Admin AI switch and company keys | Configure AI services |
| AI settings in Studio | Katalon AI Assistant Preferences |
| All AI features in Studio | Katalon AI Assistant Overview |
| Self-healing | Self-healing tests in Katalon Studio |
Katalon — Best Practices Guide. Applies to Katalon Studio 11.5 and Katalon True Platform. Screens may vary by version. Questions not covered here? Contact the Katalon Onboarding & Adoption team at onboarding@katalon.com.


