TL;DR: AI is being used to reduce false positives, prioritise exploitability, and speed remediation in application security testing, while legacy SAST, DAST, and manual review workflows struggle to keep pace with CI/CD and microservices, according to Veracode. The real shift is not tooling automation alone, but whether AppSec programmes can turn noisy detection into risk-based governance without losing developer trust.
NHIMG editorial — based on content published by Veracode: How AI is Transforming Application Security Testing
By the numbers:
- The average time to resolve vulnerabilities now exceeds 250 days, contributing to a growing mountain of security debt.
- One customer reported reducing their false positive rate from 40% with a legacy tool to just 3% in this case study.
- Veracode says AI-powered remediation improved remediation speed by over 200% in its example workflow.
Questions worth separating out
Q: How should security teams use AI-assisted penetration testing without losing trust in the results?
A: Use AI-assisted testing to widen discovery, then force a human validation step before any output becomes a confirmed finding.
Q: Why do false positives slow down appsec and DevSecOps programmes?
A: False positives slow programmes because engineers stop trusting findings that do not reliably predict real risk.
Q: What do teams get wrong about AI-assisted remediation in Microsoft environments?
A: Teams often assume AI-assisted remediation is complete when a recommendation is generated.
Practitioner guidance
- Unify AppSec findings into one risk view Correlate SAST, DAST, SCA, and runtime signals before routing work to engineering so teams review one prioritised queue instead of fragmented alerts.
- Set approval rules for AI-generated remediation Require human review for AI-suggested changes in authentication, authorisation, and other security-critical code paths.
- Measure AppSec success by outcome, not scan volume Track mean time to remediate, false positive rate, fix rate, and the percentage of findings tied to production-relevant code paths.
What's in the full article
Veracode's full article covers the operational detail this post intentionally leaves for the source:
- Examples of AI-assisted remediation inside developer workflows and IDE integrations
- Step-by-step measurement guidance for tracking MTTR, false positive rate, and fix rate
- Specific implementation examples for correlating SAST, DAST, SCA, and runtime findings
- The article's own discussion of guardrails for responsible use of AI-generated code fixes
👉 Read Veracode's analysis of how AI is transforming application security testing →
AI in AppSec testing: what it means for security teams now?
Explore further
AI is becoming an AppSec force multiplier, but only when governance keeps pace. The article correctly identifies that security teams are drowning in findings while development velocity keeps rising. AI can reduce noise and improve triage, but the programme risk is that teams mistake better ranking for better control. For IAM and adjacent governance teams, the lesson is that automation must preserve evidence, approval boundaries, and remediation accountability.
A question worth separating out:
Q: How can organisations tell whether AI pentesting is improving security?
A: They should look for reduced exposure over time, fewer repeat findings after fixes, and faster closure of issues tied to secrets or authorization logic. If retesting keeps surfacing the same problems, the programme is producing findings without changing the underlying control environment.
👉 Read our full editorial: AI is reshaping application security testing and AppSec governance