A new framework for AI penetration testing shifts the target from classic compromise to a harder question: can an attacker make a system abandon its intended mission?