Table of contents
Move faster than AI-driven risk: Inside Mend.io’s latest AI application security update
AI didn’t just change how fast you ship. It changed what your AI application security program has to protect.
Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded.
And here’s the uncomfortable part: the bottleneck was never finding vulnerabilities. Every scanner on the market can hand you a long list of findings. The real question security teams are stuck on is simpler and harder: which of these actually matter, and what do I fix first? Meanwhile, AI keeps writing more code, surfacing more vulnerabilities, and moving zero-days from disclosure to exploitation faster than most teams can triage while headcount stays exactly the same.
That’s the problem this release solves. Mend.io is expanding Mend AI and Mend AppSec with new capabilities that help security teams see what matters, fix what matters faster, and protect AI applications with confidence from development into production.
See what matters
- AI agent discovery
- AI agent configuration scan
- End of life and depreciated model detection
- Malicious package detection for containers
You cannot protect what you cannot see, and right now most organizations lack real visibility into their AI attack surface. Shadow AI, undocumented agents, and unmanaged MCP servers all sit in the blind spot between “we think we’re using AI here” and “we know exactly where and how.”
Mend AI now expands that visibility with AI agent discovery, identifying agents within applications so security teams can understand where agentic functionality is being introduced and bring it into the same inventory and governance model as the rest of their AI stack.
Once those agents are found, the new AI agent configuration risk capability scans agent configuration files for the issues that turn a helpful agent into an open door: prompt injection, command execution, credential exposure, data exfiltration, excessive permissions, and policy bypass. It extends the discovery, AI-BOM, model risk, system prompt hardening, and red teaming that Mend AI already provides across the full AI lifecycle.
Model visibility is also getting deeper. End-of-life and deprecated model detection helps teams identify AI models that are no longer supported or are approaching obsolescence, giving security and AI teams another signal for identifying technology that may introduce security, reliability, or governance risk.
Mend AppSec SCA is also expanding container risk coverage, helping identify malicious open source packages within container images and extending software supply chain visibility alongside existing vulnerability and dependency analysis.
Visibility without prioritization is just a bigger to-do list. This release gives you both.
Fix what matters faster
- Agentic triage for SAST findings
- Contextual project classification
- Zero-day response
Once you can see the risk, the next fight is prioritization and response speed. Agentic SAST triage helps distinguish true vulnerabilities from false positives and provides explanations and exploitation context, so security teams can focus investigation and remediation on findings that genuinely require action instead of manually sorting through every result.
On the application side, Mend AppSec SAST now applies Contextual Project Classification, using signals like sensitive data handling and critical functionality to sharpen prioritization. Findings stop being an undifferentiated pile and come with the context to know which ones actually matter to your business.
Zero-day response has also been tightened. Process improvements help organizations quickly determine where a newly disclosed vulnerability affects their actual application attack surface, trace exposure back to the underlying code and dependencies, and get remediation guidance so teams can prioritize based on real impact rather than treating every emerging CVE as an organization-wide fire drill.
None of this is about producing more alerts. It’s about closing the gap between finding a real risk and having it fixed, the metric that actually determines whether an organization stays ahead of an attacker or a step behind.
Protect AI in production
- AI runtime guardrails
Here’s the part that’s easy to underweight: even a well-tested AI application can behave differently once it meets real users, real data, and adversarial inputs. Prompt injection, jailbreaks, sensitive-data leakage, and unsafe responses are runtime risks by nature — they emerge through interactions that no amount of pre-deployment testing can completely anticipate. Models, prompts, tools, and agents also continue to change after release, making production the place where AI risk ultimately has to be controlled.
That’s why Mend AI runtime protection now adds real-time guardrails, deployable in-app or via a standalone proxy/API, that inspect prompts and responses for prompt injection, jailbreaks, sensitive-data exposure, exposed secrets, and unsafe content. Shift-left tells you what could go wrong before you ship. Runtime protection tells you what’s actually happening after you did. You need both.
“Mend.io has been with us for years, long before AI security, back when application security was mainly SAST and SCA,” said Alen Pešikan, Principal Engineer at SPAN. “Now Mend.io has helped us grow our program to face the risks AI brings with generated code and in the AI components themselves. Mend.io provides visibility into models, agents, prompts, and frameworks, and helps prioritize what matters most to the business. SPAN can keep up with a changing attack surface without wearing out our teams. We can see where the exposure sits, focus our resources where they count, and react fast as things change.”
What’s next: A preview of what’s coming
Mend.io is also previewing two additional AI-powered capabilities:
- AI-Based Detection, which applies AI reasoning to SAST vulnerability detection in cases where broader application context is valuable.
- Mend Intelligent Agent, which will help security teams investigate and act on application security data more efficiently.
Why this AI security approach, why now
Most AI security tools solve one piece of this problem: discovery, or prompt testing, or runtime controls, in isolation. That’s a narrower bet than the moment calls for. AI-driven risk doesn’t respect the boundary between “before deployment” and “after,” and neither should the platform meant to catch it.
Bringing AI discovery, intelligent prioritization, agentic remediation, and runtime protection together in one AI application security platform isn’t a feature checklist. It’s the only way to keep pace with how fast AI is reshaping what you have to defend. Organizations don’t need another scanner producing another list. They need to see what matters, fix what matters faster, and protect AI in production continuously, not as three separate projects run by three separate teams.
That’s what we built. That’s the mission behind every capability in this release: move faster than AI-driven risk.
See the full capabilities and book a demo at Mend.io. Mend.io will also be at Black Hat USA 2026 in Las Vegas, Aug. 4–6, at Booth #5347, schedule a meeting with the team.