The Application Security Podcast

Sarah-Jane Madden -- What AI means for AppSec

Chris Romeo and Robert Hurlbut Season 12 Episode 10

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 37:59

Sarah-Jane Madden joins Chris and Robert to ask what AI actually changes in software development—and what foundational practices still matter. Drawing on her OWASP Global AppSec EU keynote, she challenges the idea that AI makes the SDLC obsolete or turns every prompt into production-ready software. The conversation examines vibe coding, the difficulty of operationalizing AI-generated prototypes, skill atrophy, hallucinations, and the quality problems hidden by code that merely passes generated tests. Sarah-Jane argues for treating AI as a useful assistant rather than an unquestioned authority: engineers must preserve critical thinking, understand their systems, and verify the output. The episode closes with practical guidance for engineering leaders who want teams to gain efficiency from AI without surrendering judgment, accountability, or software quality.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
We provide diverse training content and easy-to-digest lessons to meet individual learner needs.
Learn more about Security Journey

Connect with Sarah-Jane Madden:
Sarah-Jane Madden on LinkedIn
Nemo Resideo keynote at OWASP Global AppSec EU

Mentioned in this episode:
Nemo Resideo keynote at OWASP Global AppSec EU
Sarah-Jane Madden — Threat Modeling to Established Teams
GitHub Copilot

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Sarah-Jane Madden: What AI Means for AppSec
02:35 From an OWASP keynote to AI in software development
04:59 The biggest misconception about AI-assisted development
07:13 Why AI will not eliminate software development
11:58 Vibe coding and the production-readiness gap
15:46 Operationalizing AI-generated prototypes
17:53 Where AI helps inside the SDLC
23:58 Over-reliance, skill atrophy, and engineering judgment
27:00 Using AI for grunt work without losing core skills
29:38 Can developers trust large language model output?
33:36 Practical guardrails for responsible AI use

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo