{"id":50952,"date":"2026-05-26T02:39:13","date_gmt":"2026-05-26T02:39:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/50952\/"},"modified":"2026-05-26T02:39:13","modified_gmt":"2026-05-26T02:39:13","slug":"are-ai-labs-coming-for-application-security","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/50952\/","title":{"rendered":"Are AI Labs Coming for Application Security?"},"content":{"rendered":"<p>In the last 90 days, every major frontier AI lab has launched a cybersecurity platform. Anthropic unveiled Project Glasswing and the Claude Mythos model, demonstrating autonomous vulnerability discovery in closed-source software. Google shipped a Gemini CLI security extension. And this week, OpenAI launched Daybreak, a multi-tiered platform built on GPT-5.5 and Codex Security, with partners including Cisco, CrowdStrike, Palo Alto Networks, and Cloudflare already integrating its capabilities.<\/p>\n<p>This isn\u2019t a single vendor doing something interesting. It\u2019s a structural shift in who builds security tooling and how fast it evolves. For security leaders, the question is no longer whether AI will reshape application security. It\u2019s whether your program is keeping pace with what\u2019s already here.<\/p>\n<p>The same AI capability that makes security analysis faster for defenders also makes it faster for adversaries. That\u2019s not a theoretical concern. It\u2019s already creating real operational pressure.<\/p>\n<p>Earlier this year, HackerOne paused its bug bounty program after AI-assisted vulnerability research led to a surge in reports that open-source maintainers couldn\u2019t process fast enough. The term the industry has landed on is \u201ctriage fatigue\u201d: too many findings, too few people to evaluate them, too little time to fix them. AI didn\u2019t create the vulnerability backlog, but it is making the backlog impossible to ignore.<\/p>\n<p>At the same time, AI-assisted development tools are producing more code, faster, than any team could write manually. More applications, more code, faster cycles. The result is a larger attack surface entering production every day, discovered by more capable adversaries, sooner.<\/p>\n<p>Most coverage frames these platforms as the beginning of the end for traditional security testing. The economics tell a different story.<\/p>\n<p>Anthropic\u2019s own published <a href=\"https:\/\/red.anthropic.com\/2026\/mythos-preview\/\" rel=\"nofollow noopener\" target=\"_blank\">Glasswing<\/a> results showed that scanning a single large codebase end-to-end cost approximately $20,000 for one review. For targeted bug discovery in specific components, the cost was roughly $50 per finding. Those numbers help explain where AI scanning excels: targeted, high-value analysis of complex code. They do not support replacing traditional application security testing across an enterprise portfolio where hundreds of applications ship code daily.<\/p>\n<p>Even Daybreak\u2019s own partners are saying the quiet part out loud. As Cisco\u2019s chief security and trust officer, Anthony Grieco told <a href=\"https:\/\/cyberscoop.com\/openai-daybreak-gpt-5-5-anthropic-mythos-cybersecurity\/\" rel=\"nofollow noopener\" target=\"_blank\">CyberScoop<\/a>, the real value \u201clies not in the model alone but in the enterprise framework built around it.\u201d That\u2019s the point. AI is a powerful component. It is not, by itself, an AppSec program.<\/p>\n<p>The credible architecture\u2014and the emerging consensus among analysts, enterprise security architects, and now the AI labs\u2019 own partners\u2014is hybrid. Deterministic, rules-based scanning for broad, fast, repeatable coverage across the portfolio. AI layered on top where it adds genuine leverage: triaging the backlog of false positives, generating remediation guidance, covering new languages quickly, and detecting vulnerability classes that require contextual reasoning rather than pattern matching.<\/p>\n<p>But whether AI replaces traditional scanning is only one dimension of a larger shift. AI is also changing what applications look like, what vulnerabilities they contain, and how developers build them. Security leaders evaluating their programs today need to account for all of these dimensions, not just the tools-versus-tools question the headlines are focused on.<\/p>\n<p>Three questions every security leader should be asking now<\/p>\n<p>Is your AppSec program covering AI-specific risks? The applications your teams are building today include large language models, AI agents, and model context protocol (MCP) servers. These introduce new vulnerability classes (prompt injection, excessive agency, data poisoning, supply chain risks in AI models) that traditional SAST wasn\u2019t designed to detect. If your vendor can\u2019t demonstrate coverage of the OWASP Top 10 for LLM Applications, you have a gap.<\/p>\n<p>Does security work where your developers actually work? AI-assisted development changed where code gets written. Developers work in IDEs, AI agents operate inside repositories, and code generation happens continuously. Security tools that only run at the end of the pipeline miss the window. Security needs to be present in the IDE, in CI\/CD, and alongside AI coding agents. Not bolted on afterward.<\/p>\n<p>How long has your vendor been investing, and what\u2019s in production? Every AppSec vendor will claim an AI strategy this year. The differentiator is what\u2019s shipping, not what\u2019s planned. Ask what\u2019s in production today. Ask when development started. Ask how triage and remediation actually work at enterprise scale. Roadmaps are easy. Shipping is hard.<\/p>\n<p><a href=\"https:\/\/www.opentext.com\/products\/application-security\" rel=\"nofollow noopener\" target=\"_blank\">OpenText Fortify<\/a> started building generative AI into SAST, DAST, and SCA in 2023. Before Glasswing. Before Daybreak. Before AI-powered security became a headline. A significant portion of the portfolio is AI-powered in production today.<\/p>\n<p><a href=\"https:\/\/www.opentext.com\/products\/application-security-aviator\" rel=\"nofollow noopener\" target=\"_blank\">OpenText Fortify Remediation Aviator<\/a> is available across on-premises, private cloud, and Fortify on Demand. It uses frontier models to audit SAST findings, separate true positives from false positives, explain each finding in plain language, and provide remediation guidance with ready-to-apply code fixes. In its first eight weeks of internal use at OpenText, Aviator audited more than 300,000 findings across 1,500 applications and reduced mean time to triage by 70%. In a market defined by triage fatigue, that\u2019s the difference between a backlog that grows and one that shrinks.<\/p>\n<p><a href=\"https:\/\/www.opentext.com\/products\/static-application-security-testing\" rel=\"nofollow noopener\" target=\"_blank\">Fortify\u2019s SAST<\/a> engine covers all ten categories of the OWASP Top 10 for LLM Applications 2025, from prompt injection to data poisoning, across the major AI frameworks and libraries. The Fortify MCP server and Fortify Agent Skills let AI coding agents work with real AppSec context, so security travels with the developer regardless of the tools they use. A next-generation VS Code extension, purpose-built for AI-powered development workflows, shipped in the 26.2 release.<\/p>\n<p>And for organizations that can\u2019t use AI tooling\u2014due to compliance, air-gap requirements, or internal policy\u2014Fortify\u2019s traditional SAST, DAST, and SCA continue getting stronger. AI features are optional add-ons, not gates on the core product. That flexibility matters. Not every organization is ready to adopt AI at the same pace, and a vendor that forces the choice isn\u2019t serving the full market.<\/p>\n<p>The bottom line<\/p>\n<p>AI didn\u2019t make application security obsolete. It made the gap between strong programs and weak ones wider and more visible. The organizations that stay ahead will treat AppSec as a program that evolves with the threat landscape, not as a checkbox that gets revisited once a year.<\/p>\n<p>Go deeper: For the full technical breakdown of Fortify\u2019s AI investment and hybrid architecture, read <a href=\"https:\/\/community.opentext.com\/cybersec\/b\/cybersecurity-blog\/posts\/ai_2d00_didnt_2d00_break_2d00_application_2d00_security\" rel=\"nofollow noopener\" target=\"_blank\">AI Didn\u2019t Break Application Security. It Exposes the Next Evolution<\/a> on the Fortify community.<\/p>\n<p>See it in action: Learn how the next-generation Fortify VS Code extension keeps security in lock step with AI-assisted development: <a href=\"https:\/\/community.opentext.com\/cybersec\/b\/cybersecurity-blog\/posts\/keeping-application-security-in-lock-step-with-ai-assisted-development\" rel=\"nofollow noopener\" target=\"_blank\">Keeping Application Security in Lock Step with AI Assisted Development<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"In the last 90 days, every major frontier AI lab has launched a cybersecurity platform. Anthropic unveiled Project&hellip;\n","protected":false},"author":2,"featured_media":50953,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,1201,30181,25,30182,30183,30184,30185,30186,30187],"class_list":["post-50952","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-ai-lab","tag-application-security-ai","tag-artificial-intelligence","tag-aviator","tag-dast","tag-fortify","tag-fortify-remediation-aviator","tag-sast","tag-sca"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/50952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=50952"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/50952\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/50953"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=50952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=50952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=50952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}