AI Is Already Inside Your SDLC. Now What?

๐€๐ˆ ๐ข๐ฌ ๐ง๐จ ๐ฅ๐จ๐ง๐ ๐ž๐ซ ๐š๐ฉ๐ฉ๐ซ๐จ๐š๐œ๐ก๐ข๐ง๐  ๐ญ๐ก๐ž ๐’๐ƒ๐‹๐‚. ๐ˆ๐ญ ๐ข๐ฌ ๐š๐ฅ๐ซ๐ž๐š๐๐ฒ ๐ž๐ฆ๐›๐ž๐๐๐ž๐ ๐ข๐ง๐ฌ๐ข๐๐ž ๐ข๐ญ. In this SafeDev Talk episode, security leaders and OWASP experts come together to examine how AI is fundamentally reshaping modern software development and why traditional AppSec governance models are struggling to keep up. The conversation explores how copilots, AI-generated code, autonomous agents, MCP-connected tooling, and machine-driven workflows are expanding the attack surface across the SDLC in ways most organizations still cannot fully see. Featuring ๐€๐ฌ๐ก๐ฐ๐ข๐ง๐ข ๐’๐ข๐๐๐ก๐ข (OWASP Global Board of Directors, ย ย /ย ashwini-siddhiย ย , ๐’๐š๐ฆ ๐’๐ญ๐ž๐ฉ๐š๐ง๐ฒ๐š๐ง (OWASP London Chapter Leader, ย ย /ย samstepanyanย ย , ๐‰๐ž๐ฌ๐ฎ๐ฌ ๐‚๐ฎ๐š๐๐ซ๐š๐๐จ (CEO at Xygeni, ย ย /ย jesus-cuadradoย ย , and ๐‹๐ฎ๐ข๐ฌ ๐‘๐จ๐๐ซ๐ขฬ๐ ๐ฎ๐ž๐ณ ๐๐ž๐ซ๐ณ๐จ๐ฌ๐š (Chief Security Research Officer at Xygeni, ย ย /ย luis-rodr%c3%adguez-xygeniย ย , this session brings together perspectives from AppSec leaders operating at the intersection of AI, software supply chain security, DevSecOps, and modern development governance. The panel breaks down how AI is changing the AppSec threat model itself. The discussion goes beyond productivity tooling to focus on operational risk: why CISOs are losing visibility across development environments, how Shadow AI is expanding inside engineering teams, why AI-generated dependencies create entirely new software supply chain risks, and how increasingly autonomous agentic workflows challenge traditional trust boundaries across the SDLC. Rather than treating AI adoption as a future concern, this episode explores the practical reality organizations already face today: maintaining visibility, attribution, governance, and continuous verification across AI-assisted software development environments operating at machine speed. โญ ๐Š๐ž๐ฒ ๐“๐š๐ค๐ž๐š๐ฐ๐š๐ฒ๐ฌ ๐Ÿ๐จ๐ซ ๐’๐š๐Ÿ๐ž๐ƒ๐ž๐ฏ ๐“๐š๐ฅ๐ค ๐€๐ˆ ๐ˆ๐ฌ ๐€๐ฅ๐ซ๐ž๐š๐๐ฒ ๐ˆ๐ง๐ฌ๐ข๐๐ž ๐˜๐จ๐ฎ๐ซ ๐’๐ƒ๐‹๐‚ โ€ข Why AI-driven SDLCs fundamentally change traditional AppSec assumptions โ€ข How Shadow AI is creating visibility and governance challenges across engineering teams โ€ข Why AI-generated code and dependencies introduce new software supply chain risks โ€ข How agentic workflows expand the attack surface beyond traditional CI/CD models โ€ข Practical approaches to securing AI-assisted development without slowing developers down This episode is highly relevant for professionals working in Application Security, DevSecOps, Software Supply Chain Security, AI Governance, Platform Security, and engineering teams adopting AI-driven development workflows. Takeaway: ๐€๐ˆ-๐๐ซ๐ข๐ฏ๐ž๐ง ๐’๐ƒ๐‹๐‚๐ฌ ๐ซ๐ž๐ช๐ฎ๐ข๐ซ๐ž ๐š ๐ง๐ž๐ฐ ๐ฆ๐จ๐๐ž๐ฅ ๐จ๐Ÿ ๐ฏ๐ข๐ฌ๐ข๐›๐ข๐ฅ๐ข๐ญ๐ฒ, ๐ ๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž, ๐š๐ง๐ ๐™๐ž๐ซ๐จ ๐“๐ซ๐ฎ๐ฌ๐ญ ๐€๐ฉ๐ฉ๐’๐ž๐œ. Subscribe to SafeDev Talks and follow Xygeni for more expert conversations on AI-aware AppSec, DevSecOps, and securing modern software development from code to runtime. #SafeDevTalks #AppSec #DevSecOps #AISecurity #CyberSecurity #SoftwareSupplyChain #AI #OWASP #AgenticAI #SecureCoding #SDLC #Xygeni

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next
โ–ถ๏ธŽ

Software Supply Chains Under Pressure: What 2025 Taught Us About Malware & AI and What Comes Next

What about Software Supply Chain Security? Essential Insights & Predictions
โ–ถ๏ธŽ

What about Software Supply Chain Security? Essential Insights & Predictions

From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec
โ–ถ๏ธŽ

From Code to Runtime: Why SAST + DAST Are Both Essential for Modern AppSec

Why The Russian Accent Terrifies Everyone
โ–ถ๏ธŽ

Why The Russian Accent Terrifies Everyone

Agentic AI and Application Security | May CISO Roundtable
โ–ถ๏ธŽ

Agentic AI and Application Security | May CISO Roundtable

THESE Apps Are SPYING on You โ€” Shut Them Off NOW!
โ–ถ๏ธŽ

THESE Apps Are SPYING on You โ€” Shut Them Off NOW!

Why Building AI Data Centres Isnโ€™t Working Anymore
โ–ถ๏ธŽ

Why Building AI Data Centres Isnโ€™t Working Anymore

Nvidia CEO Jensen Huang Interview| Bloomberg Technology Special
โ–ถ๏ธŽ

Nvidia CEO Jensen Huang Interview| Bloomberg Technology Special

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026
โ–ถ๏ธŽ

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Conan Oโ€™Brien Delivers the Commencement Address | Harvard Commencement 2026
โ–ถ๏ธŽ

Conan Oโ€™Brien Delivers the Commencement Address | Harvard Commencement 2026

Python Variables | Python Operators | Python Tutorial For Beginners | Intellipaat
โ–ถ๏ธŽ

Python Variables | Python Operators | Python Tutorial For Beginners | Intellipaat

Attacking AI - Jason Haddix - NDC Security 2026
โ–ถ๏ธŽ

Attacking AI - Jason Haddix - NDC Security 2026

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan
โ–ถ๏ธŽ

Andrej Karpathy: From Vibe Coding to Agentic Engineering w/ Stephanie Zhan

Conan Oโ€™Brien Mocks Trump At Harvard Commencement | Crowd Erupts During Viral Speech
โ–ถ๏ธŽ

Conan Oโ€™Brien Mocks Trump At Harvard Commencement | Crowd Erupts During Viral Speech

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026
โ–ถ๏ธŽ

Leading in the Age of AI: A Conversation with NVIDIA CEO Jensen Huang | Global Conference 2026

How to increase your vocabulary: Live English Class
โ–ถ๏ธŽ

How to increase your vocabulary: Live English Class

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA
โ–ถ๏ธŽ

How to Pass the Audit? Building Real AppSec aligned with ISO, NIST & CRA

Opening Keynote: Lead in the Agentic Era
โ–ถ๏ธŽ

Opening Keynote: Lead in the Agentic Era

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source
โ–ถ๏ธŽ

RL for Agents Workshop - Deep Dive on Training Agents with RL and Open Source

Nvidia CEO Live on Bloomberg Technology (full show) #tech
โ–ถ๏ธŽ

Nvidia CEO Live on Bloomberg Technology (full show) #tech