Securing The Build. RSAC 2026: Why AI Changed the AppSec Threat Model
AI broke AppSec’s assumptions: non-determinism, agent overreach, black-box models.
In this episode, the conversation lands on three reasons AI breaks the AppSec threat model. First, AI systems are non-deterministic. The same input doesn’t reliably produce the same output, so traditional test-and-validate loops fall apart. Second, AI agents tend to overreach with the permissions they’re handed, opening attack paths that conventional access controls weren’t designed to catch. Third, models are black boxes; static analysis can’t see inside them, which makes a lot of existing tooling effectively blind. The conclusion: securing AI-driven applications requires a different approach, not a louder version of the old one.
Speakers:
- Rami Sass, Co-Founder, GM Mend AI –Β Mend.io
- Amanda Glassner, Deputy Editor – Cybercrime Magazine