Will AI Replace Application Security? Navigating the New SDLC

Will AI Replace Application Security? Navigating the New SDLC

🎙 Cloud Security Podcast 👥 39K 📅 April 2, 2026 ⏱ 51 min 👁 14K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AIAppSecDevSecOpsDASTruntime security

Summary

In this episode of the Cloud Security Podcast, host Ashish Rajan interviews Joe Sullivan and Scott Gerlach about the transformative impact of generative AI on application security. They argue that traditional AppSec models, which rely on pushing back on developers with tickets, are failing due to the 10x increase in code and vulnerabilities. The discussion highlights the shift from legacy DAST to modern runtime security, which offers higher true positive rates and integrates into the development pipeline. They emphasize the need for security teams to adapt to AI-driven development, focusing on problem-solving rather than syntax memorization. The conversation also covers the evolving roles of CISOs and CIOs, the challenges of securing AI-generated code, and the importance of business logic testing. The guests share practical insights from their experience, but the episode is more opinion-based than data-driven.

136 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in the practical, real-world perspectives of two seasoned security leaders. They provide concrete examples of how AI is changing the security landscape, such as the increase in vulnerabilities and the need for runtime security. The argumentation is coherent and persuasive, particularly the critique of legacy DAST and the advocacy for modern DAST with higher true positive rates. However, the discussion is largely anecdotal, lacking empirical evidence or case studies. The guests also promote StackHawk’s product, which introduces a potential bias. Despite this, the arguments are well-structured and offer actionable insights for security professionals.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The guests rely on their extensive professional experience, which lends credibility, but they do not cite specific studies or external sources. The quality of sources is limited to the podcast’s own website and social media links. The title accurately reflects the content, focusing on AI’s impact on AppSec and the SDLC. The discussion is relevant and timely, but the lack of verifiable references and the promotional tone for StackHawk reduce the overall rigor. No comments were provided for analysis.

198 words

Title / Content Match

The title accurately reflects the core discussion about AI's impact on application security and the evolution of the SDLC.

Quality & Reliability

7/10

The podcast features two experienced security executives (Joe Sullivan, former CISO at Facebook, Uber, and Cloudflare; Scott Gerlach, CSO and co-founder of StackHawk) discussing the impact of AI on application security. Their insights are based on extensive industry experience, but the content is largely anecdotal and lacks empirical data or peer-reviewed sources. The discussion is balanced and practical, but the lack of verifiable references and the promotional context for StackHawk's DAST product slightly reduce the overall reliability.

Chapters

Cited Sources

Concurring Sources

  • OWASP Top 10 — Commonly referenced list of web application security risks.

Contribution & Novelties

The podcast provides a timely discussion on how AI is reshaping application security, offering practical advice for security teams. It challenges the traditional ‘push back’ model and advocates for runtime security as a more effective approach. The guests’ insights on the changing roles of CISOs and the importance of problem-solving over syntax are valuable.

Pour aller plus loin :

91 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, but lower in reliability and quality. This indicates a content-rich discussion with practical insights, but lacking in verifiable sources and empirical evidence.

Reliability 6/10