{{item.title}}
{{item.text}}
{{item.text}}
Frontier AI models, attacker speed, and the new role of Application Security
AI-driven vulnerability discovery is poised to overwhelm traditional approaches to remediation, forcing a rethink of its cycles, processes, and assumptions. CISOs should shed the assumptions that have long underpinned vulnerability management. Defenders can no longer count on a delay between vulnerability discovery and exploitation. That puts pressure on triage, scanner tuning, patch windows, penetration testing cycles, and human approval workflows.
Prioritization infrastructure also is under strain. Low-code and AI-generated applications are bypassing traditional software development life cycle (SDLC) controls, creating blind spots. Security teams increasingly have to make decisions before the ecosystem has fully normalized a vulnerability through common vulnerabilities and exposures (CVEs), common weakness enumerations (CWEs), scoring, and vendor guidance.
CISOs accustomed to reacting to disclosures face a new operating reality. The priority is no longer reducing vulnerability counts but identifying and containing exploitable risk. They should assume each material vulnerability is a zero-day until exploitability, reachability, and containment can be established in context. Patching remains essential, but it’s no longer sufficient as the primary approach to remediation.
Organizations should rely more on local mitigations, validated compensating fixes, trusted rebuilds, and rapid repaving while upstream fixes catch up. Resilience should focus on containment, safer and faster remediation, runtime visibility, and stronger control over what enters the codebase. Application Security (AppSec) is where these pressures converge and the response takes shape.
Frontier AI model capabilities can exacerbate the consequences of failing to operationalize fundamental security practices. Defense in depth, accurate asset inventory, stronger network and identity segmentation, and earlier software assurance are no longer just maturity goals but prerequisites for operating safely due to the following changes.
Vulnerability management is shifting from catalog-driven to exposure-driven. CVEs, CWEs, and severity scores are no longer sufficient triggers for action and, in many cases, arrive too late to matter operationally. The next trigger set comes from exploit-backed intelligence, model-assisted discovery, and vulnerability operations (VulnOps) workflows that translate those signals into internal discovery, validation, and remediation. The question isn’t if a vulnerability has been fully classified by the ecosystem but whether it’s present, reachable, chainable, and exploitable in your environment right now.
Asset management is evolving into a live operating model for faster security decisions, including those driven by agents. A quarterly configuration management database (CMDB) and a static software bill of materials (SBOM) cannot support machine-speed triage, containment, or change validation. CISOs require a runtime-truth asset graph that joins infrastructure, applications, identities, dependencies, agents, model endpoints, and deployment context. Without a connected view, security teams cannot answer the incident-hour questions that now matter most. What’s exposed? What can reach it? What can it reach?
Governance is becoming the key enabler of safe velocity. In an AI-accelerated threat environment, not every containment or remediation action can wait for human escalation, but fully autonomous action without guardrails introduces unacceptable operational risk. The emerging model is pre-approved, scoped, reversible action within clearly defined boundaries, backed by explicit authority, auditability, and rollback. Over time, leading programs will likely move beyond pre-approval toward pre-validation: simulating the blast radius of a proposed action before it executes.
The secure SDLC is being redefined as enterprises ingest production code generated outside traditional engineering channels. Business users, analysts, and product teams are already using AI tooling to generate software, agents, scripts, and integrations outside standard pipelines. “Vibe coding” has greatly accelerated the ability to develop applications, but it often prioritizes speed, user experience, and functionality over performance, resiliency, and security. That means AppSec can no longer focus only on development-stage controls. It should govern the sanctioned path for software creation and software change, including AI-assisted and citizen-developed output from initial generation through release and remediation.
The priority isn’t simply to accelerate individual controls but to redesign the security operating model across the functions most affected by AI-compressed attack timelines: vulnerability management, SOC, defensive engineering, identity, infrastructure, and AppSec. CISOs should reposition their programs around five imperatives.
CISOs should coordinate AI-enabled transformation across pressured functions rather than pursuing disconnected point solutions. Together, these functions should evolve toward a common operating model built on shared telemetry, faster validation, and bounded automation.
AppSec and vulnerability management are converging into a continuous validation function. These functions sit closest to the places where AI is already changing cyber risk: software change, dependency risk, remediation velocity, and the growing volume of AI-assisted development. They’re also where the pressure from compressed discovery-to-exploit timelines is likely to show up first and most visibly. This has three direct consequences.
Two patterns support this shift toward continuous validation: LLM-assisted code-review through semantic control analysis to strengthen detection and evidence, and the self-healing pipeline to close the loop with bounded remediation.
Make AI-assisted semantic code review a control, not a pilot.
Insert AI-assisted semantic code review into your pull-request path and map results to the frameworks that matter to your business. Treat it as an evidence-producing control to accelerate validation you require for prioritization and post-fix retesting.
Establish a sanctioned path for AI-generated code.
Business-led and AI-assisted development will likely continue whether you approve it or not. The right response is to make the secure path easier than the shadow path: approved tools, required checks, provenance capture, and mandatory review.
Stand up VulnOps as a named capability.
The discover-prioritize-fix-validate loop requires clear ownership and tighter integration across your security and engineering teams. A dedicated function can reduce the gap between finding, validation, and safe remediation.
Pilot bounded self-healing remediation.
Start with routine dependency and configuration fixes in your CI/CD where rollback is well understood. Define clear scope boundaries, validation gates, and audit requirements from the outset.
Contributors: Jessica Hale
{{item.text}}
{{item.text}}