AI in the SDLC: Separating the Hype from the Security Reality
Autonomous AI development isn't coming, it's already here. McKinsey found that 31% of enterprises now run at least one AI agent in production, many in high-stakes environments like banking, financial services, and healthcare.
Implementation of autonomous AI agents is outpacing regulation, and the risk signals are alarming. Secure Code Warrior and RMIT University research found no universally secure AI coding model. AI-generated code carries an average of 15 vulnerabilities per codebase. Every developer, even "citizen developers," needs to understand the risks before code reaches production.
Secure Code Warrior and KnowBe4 are teaming up to unpack the market shifts driving this change and the vulnerability patterns showing up in AI generated code. Earlier this year, the two partnered to bring secure coding content into KnowBe4's attack simulation and training library. In this live webinar, they’ll share practical techniques for reducing AI development risk.
KnowBe4 CISO Advisory Kawin Boonyapredeeto will discuss software development's evolution from compilers and CI to today's goal-driven AI agents. He'll cover:
- The engineer's job is shifting from writing code to directing it
- Guardrails, specs, and verification are now core engineering skills
- What this shift means for security and engineering leaders
SCW CEO and Co-Founder Pieter Danhieux will dive into the results of the SCW AI Trust Index, a benchmark of how often leading AI coding models generate vulnerable code. He'll share key highlights from the research, including:
- No model is universally secure: 15 vulnerabilities per codebase, on average
- Vulnerability patterns repeat across auth, input validation, database, and API code
- How to detect AI and MCP influence in your pipeline and reduce the risk
Don't miss this live session to learn how you can make more secure, cost-effective, and contextually relevant choices when integrating AI tooling into your tech stack.
Explore more events and webinars
Access expert content on secure coding, AI governance, and software risk management.
%252520(1).avif)
OWASP Global AppSec USA
Proud to be a Silver Sponsor of OWASP Global AppSec USA 2026, celebrating its 25th anniversary on November 5–6, 2026, at the Hyatt Regency in San Francisco! Join us and 800+ application security professionals for sessions on AI security, threat modeling, a Capture the Flag competition, the OWASP Projects Demo Room, and exclusive networking receptions. Come find us there and let's connect!

OWASP LASCON
We are proud to be a Gold Sponsor for OWASP LASCON 2026 in Austin, TX! Join us at the Norris Conference Center as we gather with over 400 web developers and security professionals to share cutting-edge ideas in application security.

Registration test
In the world of AppSec, a strong brand is essential for lasting program impact. Jim Loughran, Principal Consultant at Secure Code Warrior, highlights how a powerful program identity can bridge the gap between security and engineering, fostering developer buy-in and sustained engagement. Join him to learn how to create and leverage a brand to ensure your secure coding initiatives truly shine, turning a great program into a great success story.
Secure AI-driven development before it ships
See developer risk, enforce policy, and prevent vulnerabilities across your software development lifecycle.
