Listening guide
AI security podcast episodes for AppSec engineers
The Application Security Podcast, hosted by Chris Romeo and Robert Hurlbut, has covered AI and LLM security in 30 episodes. This guide groups conversations on securing AI agents, AI code review and AI-written code, AI in security testing, the AppSec program in the AI era, and AI security standards. It is for AppSec engineers who want to understand what changes in their work and which security practices still need attention.
Start with these three
Three recent conversations on agent access, generated code, and code review.
Securing AI agents
How Agentic AI Fails—and Which Controls Actually Stop It
Petra Vukmirovic · September 15, 2026 · 37 min
Petra Vukmirovic applies fault tree analysis to a customer-refund agent scenario. She explains how failure paths help rank controls and connect security decisions to their consequences.
“You need to make sure you give it the right information in the right structure with the right constraints and the right guidelines.”
Steve Wilson--OpenClaw and Advanced AI Agents
Steve Wilson · April 15, 2026 · 50 min
Steve Wilson examines the permissions, memory, and actions that distinguish agents from chatbots. He discusses prompt injection, source-code exposure, and the limits of current oversight.
“You want to wall it off somewhere where you get a little control over it.”
Francesco Cipollone - Agentic AI Manifesto
Francesco Cipollone · September 23, 2025 · 33 min
Francesco Cipollone separates agents from chatbots with tools and explains why his team uses specialized models. He argues for observable, bounded automation that solves a defined problem.
“Like, we need to embrace and adopt this technology and understand how to use it and how to 10x people.”
AI code review and AI-written code
Why AI Code Review Will Replace Human Review Faster Than You Think
Jim Manico · September 29, 2026 · 49 min
Jim Manico explains his AI coding workflow, including architecture files, security rules, and planning. The hosts debate how AI review changes education and what vague prompts leave unchecked.
“Focus on the technical, the experience, the practice, the technical guides, and learn the technology first, then go complain about it, right?”
Tanya Janca - Secure Vibe Coding
Tanya Janca · April 30, 2026 · 48 min
Tanya Janca explains why generated code still needs explicit requirements and independent testing. She shares examples of removed error handling and models confidently reviewing their own insecure output.
“You should treat AI like a junior developer.”
Josh Grossman--AI & SAST: Is it a match?
Josh Grossman · June 2, 2026 · 40 min
Josh Grossman combines static discovery with LLM analysis in AGHAST. He explains where context helps, how false positives and token costs affect adoption, and why humans retain responsibility for review.
“You have to ask Claude to build you an emulator for it.”
Michael Burch - AI-Enabled Citizen Developers
Michael Burch · June 16, 2026 · 49 min
Michael Burch examines the risk of employees generating software before organizations set boundaries. He argues for sandboxed workflows, automated controls, and outcomes measured beyond tool adoption.
“we have to make sure what we want to do aligns with the business case.”
Your Opinion on AI Doesn't Matter. Learned Fragility Does
Brook S.E. Schoenfield · October 5, 2026 · 53 min
Brook Schoenfield questions the confidence that makes AI output feel finished. The hosts examine what happens when teams accept generated software without understanding how it works.
“But wherever you have greater needs, it really is not wrong to get an expert in there to, to finish the job.”
Security testing and the AppSec program in the AI era
AI Pen Testing Killed Traditional DAST
James Berthoty · August 31, 2026 · 44 min
James Berthoty argues that adaptive AI penetration testing differs from traditional scanning. The conversation examines application context, token costs, and limits on autonomous testing.
“Like, first of all, vendors will always choose the pricing structure that maximizes the cost.”
Vulnerability Jail and the AI-Era AppSec Engineer
Jeevan Singh · September 22, 2026 · 45 min
Jeevan Singh describes controls for teams producing much more code, including restrictions on non-compliant changes. He discusses agents that search for vulnerability classes and how the AppSec role is changing.
“So we had Vulnerability Jail already, but now we're going to be changing SLAs to 3, 5, 7, and 10.”
Isaac Evans - AppSec in the Age of AI
Isaac Evans · July 28, 2026 · 49 min
Isaac Evans discusses security controls moving from CI into coding agents. He explains organization-specific analysis and why independent verification still matters.
“I'm going to suggest that this rule be promoted to the code generation loop across the entire org.”
Brad Geesaman - Redefining AppSec with AI: Shrinking Toil, Expanding Impact - How LLMs are able to reduce toil in triage-heavy AppSec workflows
Brad Geesaman · October 28, 2025 · 42 min
Brad Geesaman explains how LLMs can assist classification, evidence gathering, and contextual analysis. He keeps humans responsible for final decisions while exploring ways to reduce repetitive triage.
“Yeah, to your point, AI to get funding, but I think that there's reality, there's quality within the hype that gets drowned out.”
Standards, secrets, and frameworks
AI Security: OWASP Meets Global Standards
Rob van der Veer · August 26, 2026 · 48 min
Rob van der Veer explains efforts to align AI security standards through OWASP AI Exchange and MOSAIC. The conversation asks how teams can turn that guidance into practices for AI systems and generated code.
“red teams really need to think about sequences of events, cunning sequences that can lead to harm and that circumvent certain protections.”
Caroline Wong--The AI Cybersecurity Handbook
Caroline Wong · April 21, 2026 · 45 min
Caroline Wong examines the gap between software production and security capacity. She discusses architecture, visibility, and evaluating trust through accuracy, reliability, explainability, and accountability.
“if attackers are using AI, defenders can use AI.”
Dwayne McDaniel -- Secrets Sprawl and How AI is Impacting Secrets
Dwayne McDaniel · May 14, 2026 · 45 min
Dwayne McDaniel discusses how AI coding tools and MCP templates contribute to exposed credentials. The conversation moves from detection toward short-lived identity, ownership, and feedback loops.
“there's a false sense of security that I'm doing this internally.”
More AI security from Chris Romeo
AI Security Table (formerly The Security Table) is the roundtable podcast where Chris Romeo, Izar Tarandach, and Matt Coles debate how to secure AI systems and how AI changes software security. Explore its AI agent security guide for more conversations on permissions, MCP, and prompt injection.