SAINTCON 26 · Session

The End of Human-Scale AppSec

Speakers
  • @cktricky · CTO & Co-Founder @ DryRun Security

**The End of Human-Scale AppSec: Governing an Agentic Workforce**

For decades, application security programs have been built around a simple assumption: humans are the primary producers of software. We train developers, review pull requests, conduct threat modeling exercises, and build controls around human decision-making.

That assumption is rapidly breaking down.

AI coding assistants are evolving into autonomous agents capable of designing, writing, testing, reviewing, and deploying software. As organizations adopt these systems to increase velocity and remain competitive, AppSec teams face a fundamental challenge: how do you govern an engineering workforce that is increasingly non-human?

In this session, Ken Johnson, CTO of DryRun Security, explores the implications of agentic software development for application security. We'll examine which security practices are likely to survive, which must fundamentally change, and where traditional approaches may become bottlenecks rather than safeguards. We'll discuss the ramifications for threat modeling, code review, security testing, change management, accountability, and governance as software production scales beyond human capacity.

Most importantly, we'll explore how security teams can adapt. Attendees will leave with a framework for evaluating emerging AI-driven development practices, understanding the risks and opportunities of agentic systems, and preparing their organizations for a future where software is increasingly created, reviewed, and maintained by AI agents operating at machine speed.

← Full schedule

Security Briefing

Join the mission log

Occasional emails with training announcements, CFP windows, and what's launching at SAINTCON. No spam, no selling your address. Ever.

By subscribing you agree to the Privacy Policy.