Conference40min
Has AI Broken Application Security Forever?
Generative AI is accelerating Java development, modernization, and remediation, but also increasing the volume and speed of code changes beyond human review. This talk examines AI-generated code, insecure dependencies, supply chain risks, trust in automated fixes, and the security controls needed to adapt.
talk.summaryAiDisclaimer
Steve PooleHeroDevs
talkDetail.whenAndWhere
Friday, November 20, 15:05-15:45
Room 2 - Alexandros
talks.roomOccupancytalks.noOccupancyInfo
Generative AI can now write, explain, test and modernise Java code at a pace that puts real pressure on traditional secure development. But what happens when AI starts influencing hundreds or thousands of changes across an application?
There’s an obvious upside. AI can help teams modernise legacy systems, remove technical debt, generate tests, and tackle work that may have sat in the backlog for years. But it also creates a new problem: more code is changing faster, often in ways that are difficult for humans to review in detail.
So what does “secure development” look like when the developer is no longer the only one writing the code?
In this talk, we’ll cover AI-generated code, insecure dependencies, software supply chains, automated remediation, trust in generated fixes, and the controls we still need around AI-assisted development.
We’ll also look at where AI can genuinely improve security and where it simply lets us make mistakes faster.
AI hasn’t made application security irrelevant. But it has broken some of the assumptions our security processes were built on. The question now is whether our security practices can evolve quickly enough to keep up.
There’s an obvious upside. AI can help teams modernise legacy systems, remove technical debt, generate tests, and tackle work that may have sat in the backlog for years. But it also creates a new problem: more code is changing faster, often in ways that are difficult for humans to review in detail.
So what does “secure development” look like when the developer is no longer the only one writing the code?
In this talk, we’ll cover AI-generated code, insecure dependencies, software supply chains, automated remediation, trust in generated fixes, and the controls we still need around AI-assisted development.
We’ll also look at where AI can genuinely improve security and where it simply lets us make mistakes faster.
AI hasn’t made application security irrelevant. But it has broken some of the assumptions our security processes were built on. The question now is whether our security practices can evolve quickly enough to keep up.
Steve Poole
Accomplished technical leader and developer advocate with over three decades of experience in software engineering, DevOps, developer advocacy, and security, especially cybercrime and software supply chains. Recognised international public speaker and author on software supply chain security, AI, and cybercrime legislation, with a deep background in engineering and DevOps leadership. Proven track record in driving product innovation, improving development processes, and fostering vibrant open-source communities.