Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI-powered application security and DevSecOps: what teams need now


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI-generated code now touches most development teams, while 74% of organisations still carry critical flaws that can persist for months or years, according to Veracode and the 2025 State of Software Security Report. Fragmented toolchains and slow remediation are becoming the real bottleneck, not development speed.

NHIMG editorial — based on content published by Veracode: Revolutionizing DevSecOps with AI-Powered Application Security

By the numbers:

Questions worth separating out

Q: How should security teams secure AI-assisted development without overwhelming AppSec workflows?

A: Start with continuous discovery, then connect findings to exposure, criticality, and data sensitivity before remediation begins.

Q: Why do AI-generated code pipelines create more security risk than traditional development?

A: They compress the time between defect creation, discovery, and exploitation.

Q: What do teams get wrong about AI-generated remediation suggestions?

A: They often treat the suggestion itself as authoritative.

Practitioner guidance

  • Create one risk model for AppSec tooling Correlate SAST, DAST, SCA, and posture findings into a single prioritisation flow so teams stop triaging the same weakness in multiple tools.
  • Governing AI-assisted remediation Require curated fix patterns, code review rules, and exception handling for AI-generated remediation suggestions before they are trusted at scale.
  • Map identity controls to the delivery pipeline Inventory CI/CD service accounts, build tokens, package registry access, and deployment credentials, then remove standing privilege wherever possible.

What's in the full article

Veracode's full article covers the operational detail this post intentionally leaves for the source:

  • How AI-powered application security tools are integrated into IDEs and CI/CD pipelines without changing developer workflows
  • The case study metrics behind the claimed 92% faster mean time to remediation and 70% fix acceptance rate
  • The specific way Veracode frames ASPM, runtime protection, and policy enforcement across the development lifecycle
  • The source's discussion of AI-generated code, vulnerability testing, and supply chain controls in one programme model

👉 Read Veracode's analysis of AI-powered application security in DevSecOps →

AI-powered application security and DevSecOps: what teams need now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-powered application security is really a governance response to software velocity. The core issue is not that security teams lack tools, but that AI-assisted development has shortened the window between code creation and code exposure. That makes traditional manual review too slow for the pace of modern delivery, especially when secrets, dependencies, and access decisions are embedded in build and deploy workflows. Practitioners should treat AppSec as a control system tied to release velocity, not a separate inspection layer.

A question worth separating out:

Q: How can organisations tell whether their AI security model is actually working?

A: They should test whether the control stack can explain who acted, what data was touched, and what purpose the action served. If those three signals cannot be correlated in one incident view, the model is likely monitoring access without governing behaviour. That is a visibility gap, not a complete AI security posture.

👉 Read our full editorial: AI-powered application security is changing DevSecOps economics



   
ReplyQuote
Share: