In 2026, AI isn’t just assisting developers — it’s writing production code, generating tests, reviewing pull requests, and proposing fixes at a velocity no human team can match. Models like Claude Opus and other autonomous agents are embedded directly into the software supply chain.
At the same time, adversaries are using AI to discover and exploit vulnerabilities faster than most organizations can even detect them.
This isn’t incremental change.
This is a structural shift.
The old AppSec model — static scans, ticket queues, late-stage reviews, “shift left” slogans — was already buckling under modern DevOps. Now it’s dangerously behind. When code is created at machine speed, security must operate at machine speed.
So the real question is no longer “How do we improve AppSec?”
It’s:
In a world where AI writes, tests, and fixes code — and criminals use AI to break it — what exactly is the mission of AppSec?
Hosted by the editors of DevOps.com and Security Boulevard, this Techstrong editorial roundtable brings together AppSec leaders, DevSecOps practitioners, and platform engineering experts to tackle the hard realities of AI-native software development.
We will confront:
This is not another “shift left” conversation.
This is about defining AppSec’s role in a post-AI world.
If AI is generating your code, reviewing your code, and fixing your code, then security must evolve from reactive enforcement to autonomous, real-time orchestration.
The organizations that figure out where humans leave off, and machines take over, will build resilient systems.
The ones that don’t will be defending yesterday’s perimeter against tomorrow’s attacks.