Skip to content
AppSec PodcastThe Application Security Podcast — home
37 minSeason 13, episode 12

How Agentic AI Fails—and Which Controls Actually Stop It

With Petra Vukmirovic

Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Sponsored byCorgeaAI-native application security from design to production.Learn more ↗
Episode chapters · 18 chapters
  1. 00:00Cold open — the math behind where to put your controlsAudioVideo ↗
  2. 01:09Meet Petra VukmirovicAudioVideo ↗
  3. 01:28Petra's origin story: from ER doctor to AppSecAudioVideo ↗
  4. 02:50Career path: engineer to Head of InfoSec at NumanAudioVideo ↗
  5. 04:18What is fault tree analysis, and where threat modeling endsAudioVideo ↗

About this episode

Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a “wrong customer refund” AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why “comprehensive test coverage” is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.

This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.

About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
Learn more about Corgea

Connect with Petra Vukmirovic:
Petra Vukmirovic on LinkedIn
OWASP Threat Model Library

Resources
Adam Shostack: “Stop Trying to ‘Manage Risk’” (keynote)
OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)

Get Reasonable AppSec: new episodes and useful picks from the archive.