Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Isaac Evans - AppSec in the Age of AI

49 min28 juli 2026

Om avsnittet

AI is moving AppSec's control point out of CI and directly into the coding agent—but what happens when the model writing the code is also expected to secure it? Semgrep co-founder and CEO Isaac Evans explains why deep background analysis and real-time agent plugins may replace universal rule sets with organization-specific security controls. He and Chris explore how security engineering roles will change, why independent verification still matters, and where business-logic flaws may become the next major battleground. The conversation also covers vibe coding at enterprise scale, the limits of reasoning about model behavior, open source in an agent-built world, and why Isaac sees more opportunity than threat even as AI creates a fresh wave of vulnerabilities and cleanup work.

Connect with Isaac Evans:
Isaac Evans on LinkedIn
Semgrep

Mentioned in this episode:
Semgrep
DeepSeek
Cursor
OpenAI Codex
Claude Code
Boston Dynamics
DARPA Robotics Challenge
Reflections on Trusting Trust
uutils/coreutils
Rust

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Isaac Evans
01:11 From cryptography to the DARPA Robotics Challenge
03:43 Founding Semgrep
04:05 How AI is reshaping AppSec
06:15 Attackers, defenders, and model choice
08:02 Regenerating code until it clears the security bar
10:30 Organization-specific rules beat universal rules
14:18 The changing role of the security engineer
17:53 Career advice for security practitioners
19:47 Will foundation models absorb security vendors?
24:18 Getting secure changes across an enterprise
26:40 Trusting Trust becomes the easy problem
27:41 How much should we trust agent-generated code?
29:38 Independent verification and competing models
34:50 Business logic flaws after SQL injection
36:56 Protecting the new wave of citizen developers
39:40 Vibe coding and disposable software
42:05 Open source in an agent-built world
44:10 Can the exponential pace continue?
44:41 Key takeaways and calls to action

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.