Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

How Agentic AI Fails—and Which Controls Actually Stop It

37 min15 september 2026

Om avsnittet

Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.

This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.

About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
Learn more about Corgea

Connect with Petra Vukmirovic:
Petra Vukmirovic on LinkedIn
OWASP Threat Model Library

Mentioned in this episode:
Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)
OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)

Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

Chapters:
00:00 Cold open — the math behind where to put your controls
01:09 Meet Petra Vukmirovic
01:28 Petra's origin story: from ER doctor to AppSec
02:50 Career path: engineer to Head of InfoSec at Numan
04:18 What is fault tree analysis, and where threat modeling ends
06:22 Can AI actually do fault tree analysis?
08:12 Walking the "wrong customer refund" agent example
12:33 Storing your trees: JSON vs. Markdown
16:08 Why conjunctive failures trip up narrow thinking
17:27 Top 3 failure modes when agents touch downstream systems
19:29 Real story: an agent pushed code to main without approval
21:27 Testing: why "comprehensive coverage" is a myth
23:54 How rough is rough? Assigning probabilities
28:08 Getting started without a six week science project
31:35 Using FTA to sell controls and build credibility
33:43 The epiphany: FTA is about controls, not faults
34:48 The one thing every agentic team should add today
35:48 Closing thoughts and OWASP Global AppSec USA preview

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.