AI Application Security: Why AppSec Isn't Dead in the AI Coding Era
For a while, the line going around was that AI coding assistants would make application security obsolete: write secure code by default and eliminate the need for scanners. The founders actually building AppSec tooling right now tell a different story: AI hasn't killed the category, it's multiplied the problem it exists to solve.
The Vulnerability Count Didn't Go Down
James Wickett and Ken Johnson, co-founders of DryRun Security, put that assumption to the test directly. They ran Claude, Codex and Gemini through identical coding tasks and scored the output. "None of them were great," James says, adding that Codex performed best, Claude worst, but all three produced "authorisation, authentication, broken access problems, logic flaws that are kind of baked in." Across the exercise they found 140 vulnerabilities, roughly seven to ten per app.
What's changed isn't the vulnerability rate, Ken argues, it's the velocity. "That noise changes when you go from making ten changes a day to thousands." One customer's pull request volume tripled from 20,000 to 60,000 a month. Old-style scan-and-ticket tooling wasn't built for that pace: "All you're going to get is buried in alerts that don't matter." James is blunt about where that leaves the legacy approach: "Run a scan, file some tickets, maybe somebody's going to prioritise it next month, that's dead." What replaces it, he says, is closer to "risk governance" than traditional scanning, and on the state of the discipline itself, he's optimistic: "AppSec's never been more alive."
When Anyone Can Ship an App, Anyone Can Ship a Breach
Tristan Kalos, CEO of Escape, is watching that same shift from the offensive side. His team tested over 2,000 "vibe-coded" applications and found 1,500 critical vulnerabilities and 125 live data leaks, some built by people with zero security background. "Some of those applications have been built by doctors," he says, managing patient data through platforms that made building the app trivial and securing it an afterthought. His read on the underlying dynamic: "When you double the size of the business, you're not doubling the size of the security team," while "the very same models used to build code" are also being used to attack it.
Winning trust with engineering teams, Tristan says, is the real constraint on any tool trying to fix this: "You cannot afford to produce false positives." Get that wrong and a security tool just becomes more noise engineers learn to ignore.
Reviews Are the Bottleneck Nobody Talks About
Emily Choi-Greene, CEO of Clearly AI, is attacking a different part of the pipeline: the review itself. "Developers launching five times more code with AI" has pushed enterprise security and compliance reviews into multi-month backlogs, and code is only part of it. "75% of the reviews that we run are data privacy, vendor reviews, compliance, AI governance," she says. Her goal is to compress that timeline "down to minutes." On hiring, her pitch leans on authenticity over polish: "Built by security engineers for security engineers... we're very transparent and open," with above-market equity so early hires "feel like true owners."
What This Means for Hiring
The through-line across all three conversations is that AppSec is shifting from periodic scanning toward continuous, engineering-embedded judgment. Teams need engineers who can build tooling that developers actually trust, with low false-positive rates and deep integration into CI/CD, rather than another dashboard nobody checks. On the security side, that means fewer generalist scanner operators and more people fluent in both offensive security and the realities of AI-assisted development.
Bottom Line
- AI coding tools haven't reduced vulnerabilities; they've multiplied both the code volume and the blast radius of any weakness.
- Legacy scan-and-ticket AppSec is dead; what's replacing it is continuous, trust-based tooling embedded in the engineering workflow.
- The founders winning this space are hiring for judgment under noise, not just security credentials.
Building AppSec, offensive security or secure development tooling for the AI coding era? Talk to Aspiron Search about finding the engineering and security talent to get there first.