{"id":102565,"date":"2025-06-25T18:06:20","date_gmt":"2025-06-25T16:06:20","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?post_type=learn&#038;p=102565"},"modified":"2025-06-25T18:06:21","modified_gmt":"2025-06-25T16:06:21","slug":"leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy","status":"publish","type":"learn","link":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/","title":{"rendered":"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy"},"content":{"rendered":"<p>Application security is at a breaking point. Codebases are growing exponentially \u2013 driven by microservices, rapid release cycles, and AI-generated code \u2013 yet AppSec teams aren\u2019t scaling at the same pace. Manual triage, reactive scans, and developer fatigue are making modern security feel unsustainable, which by contrast, can make the allure of AI agents feel especially exciting.<\/p>\n\n\n\n<p>These autonomous, intelligent tools deliver promise across the entire software development life cycle (SDLC), creating new ways to scan, prioritize, and remediate vulnerabilities without adding headcount or slowing development velocity. As&nbsp; AI continues to drive enhancements, AppSec is transforming in real-time. Here&#8217;s what it means for DevOps engineers on the front lines.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\"><strong>The AI Era: Why AppSec Needs to Adapt Faster<\/strong><\/h2>\n\n\n\n<p>While AI is accelerating software development, it is also introducing a new class of risks that traditional AppSec workflows can\u2019t keep up with. Offensive AI agents are beginning to outpace human hackers in speed and sophistication, launching attacks that exploit zero-day vulnerabilities, bypass detection tools, and adapt dynamically in real time. These threats don\u2019t wait for your next sprint or quarterly scan.<\/p>\n\n\n\n<p>At the same time, AI is contributing massively to the development process: generating code, writing tests, and even managing infrastructure. But the benefits come with caveats. According to Google\u2019s 2024 DORA report, a 25% increase in AI adoption is associated with a 1.5% decrease in production throughput and a 7.2% decline in delivery stability.<\/p>\n\n\n\n<p>This paradox creates a new imperative: If AI is generating more code and more risk, then preventive and defensive AI agents must rise in parallel. Autonomous, in-IDE remediation agents powered by multi-agent architectures can provide just-in-time guidance and secure-by-default code suggestions, catching flaws before they ever leave a developer&#8217;s local environment.<\/p>\n\n\n\n<p>In this new era of accelerated innovation and adversarial automation, intelligent, embedded AppSec is the baseline requirement for secure, scalable software delivery.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\"><strong>Why AI Readiness Matters: The Foundation for Agentic AppSec Success<\/strong><\/h2>\n\n\n\n<p>AI agents can transform how organizations detect, prioritize, and remediate security issues, but they don\u2019t operate in a vacuum. Their success depends heavily on an organization\u2019s overall AI maturity.<\/p>\n\n\n\n<p>AppSec agents are most effective in environments that already treat AI as a strategic enabler, not a novelty. If your development teams are still adjusting to basic AI-assisted workflows, or your security data is scattered across siloed tools, agents will lack the context they need to deliver meaningful results.<\/p>\n\n\n\n<p>The most successful deployments happen in organizations that have already invested in:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Clean, connected security data<\/strong> like SBOMs, prior findings, and contextual risk models<\/li>\n\n\n\n<li>\n<strong>AI-aware development culture<\/strong>, where engineers are comfortable collaborating with machine-generated suggestions<\/li>\n\n\n\n<li>\n<strong>Clear governance frameworks<\/strong>, ensuring agent decisions are explainable, auditable, and aligned with policy<\/li>\n<\/ul>\n\n\n\n<p>Without that foundational maturity, agentic AppSec can feel like another tool rather than a force multiplier. But for teams that are already building with AI in mind, autonomous agents become a natural extension of existing workflows, accelerating secure development rather than disrupting it.<\/p>\n\n\n\n<p>In short, AI agents amplify what\u2019s already working. If you\u2019ve laid the groundwork, technically and culturally, they can scale your AppSec efforts with speed, intelligence, and precision.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\"><strong>What Are AI Agents in the AppSec Context?<\/strong><\/h2>\n\n\n\n<p>An <strong>AI agent<\/strong> is a self-directed entity that can perceive its environment, reason about what it sees, and take action to achieve a goal. In AppSec, these agents can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Identify vulnerabilities<br>\n<\/li>\n\n\n\n<li>Assess business risk<br>\n<\/li>\n\n\n\n<li>Suggest secure code changes<br>\n<\/li>\n\n\n\n<li>Enforce policy<br>\n<\/li>\n<\/ul>\n\n\n\n<p>Also known as <strong>agentic AI<\/strong>, the autonomous systems are often used to augment or replace specific human tasks, especially those that are repetitive, error-prone, or time-intensive. When done correctly, the goal isn&#8217;t to eliminate humans from the process, but to allow AppSec and DevOps professionals to focus on strategic analysis, edge-case vulnerabilities, and high-value engineering work all in one platform.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\"><strong>What Are Multi-Agent Networks in AppSec?<\/strong><\/h2>\n\n\n\n<p>Rather than one monolithic model,<a href=\"https:\/\/checkmarx.com\/blog\/multi-agent-networks-in-appsec-the-future-of-collaborative-autonomous-security\/\"> multi-agent networks<\/a> use purpose-built AI agents for AppSec that specialize in different parts of the AppSec lifecycle. This architecture can suggest secure code fixes in IDEs and pull requests; contextualize findings, scores risk, and prioritizes triage; and enforce security policy and regulatory alignment.<\/p>\n\n\n\n<p>These agents collaborate in real time by sharing insights, validating each other\u2019s decisions, and providing a cohesive security experience. Think of it as a distributed security brain operating continuously across your SDLC.<\/p>\n\n\n<section class=\"section-block-info light-theme\">\n    <div class=\"main-wrapper block-info__wrapper\">\n        <div class=\"block-info center\">\n\t\t\t\n\t\t\t<h2 class=\"section-title article-anchor\" id=\"article-anchor-5\">Rethink What\u2019s Possible with AI Agents in AppSec<\/h2>\t\t\t<p class=\"section-description\">Discover how multi-agent systems are automating triage, prioritization, and remediation without slowing down development.<\/p>\n\t\t\t<div class=\"actions\">\n\t\t\t\t        <a href=\"https:\/\/checkmarx.com\/blog\/multi-agent-networks-in-appsec-the-future-of-collaborative-autonomous-security\/\" class=\"btn btn-2 btn-bg white demo\">Read the full breakdown on collaborative autonomous AppSec<\/a>\n        \t\t\t\t\t\t\t<\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\"><strong>Triaging at Scale: Letting AI Handle the Noise<\/strong><\/h2>\n\n\n\n<p>Traditional scanners overwhelm engineers with unfiltered alerts whereas AI agents are able to reduce noise in AppSec by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Filtering out false positives<br>\n<\/li>\n\n\n\n<li>Scoring findings by business impact<br>\n<\/li>\n\n\n\n<li>Tying vulnerabilities to specific assets and threat models<br>\n<\/li>\n<\/ul>\n\n\n\n<p>Instead of assessing every vulnerability equally, intelligent AI agents can decipher what matters most and prioritize accordingly. This accelerates MTTR (mean time to remediation) and reduces the triage burden on DevOps.<\/p>\n\n\n\n<p>Detection is only half the battle, though. Many developers don\u2019t inherently know how to fix a vulnerability, or they introduce regressions when they try. AI agents can help by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Suggesting fixes inline<br>\n<\/li>\n\n\n\n<li>Matching fixes to secure code patterns<br>\n<\/li>\n\n\n\n<li>Ensuring code style and test compliance<br>\n<\/li>\n<\/ul>\n\n\n\n<p>But this comes with risk. AI-generated fixes can be wrong or incomplete, underscoring the importance of AI augmentation rather than replacement with human talent.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\"><strong>Guarding the Guardians: Securing the AI Agents<\/strong><\/h2>\n\n\n\n<p>Before employing AI agents, DevOps engineers must understand the full set of risks that accompany their capabilities. Key areas to watch out for include:&nbsp;&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>LLM poisoning<\/strong>: Malicious actors may introduce biased or backdoored code examples into public repositories or training sets. For example, injecting insecure code patterns into open source libraries that agents use to learn remediation techniques could lead agents to consistently recommend vulnerable fixes.<br>\n<\/li>\n\n\n\n<li>\n<strong>Prompt injection<\/strong>: If an agent relies on natural language input or instruction chains (e.g., from developers or other agents), an attacker could embed hidden directives that alter the agent\u2019s behavior. For instance, a prompt like \u201cignore this security rule\u201d buried in a code comment or PR description might trigger unsafe actions if not properly sanitized.<br>\n<\/li>\n\n\n\n<li>\n<strong>Misuse<\/strong>: Without strong access controls, agents could unintentionally scan and expose internal or sensitive codebases. A misconfigured agent might upload analysis results or logs to an external server or mistakenly ingest proprietary source code into its learning model, violating privacy and compliance boundaries.<br>\n<\/li>\n<\/ul>\n\n\n\n<p>To secure AI agents effectively, organizations should start by enforcing fine-grained access controls through Role-Based Access Control (RBAC). This ensures that each agent can only access the data and systems it absolutely needs, reducing the blast radius in the event of misuse or compromise.<\/p>\n\n\n\n<p>Next, all inputs to AI agents, whether user commands, prompts, or code snippets, should be rigorously sanitized and validated. This helps prevent prompt injection attacks or the accidental ingestion of malicious or malformed data.<\/p>\n\n\n\n<p>Finally, it is critical to maintain immutable logs and decision audit trails. Every action an agent takes, from triage decisions to remediation suggestions, should be logged in a tamper-proof system. This allows teams to trace behavior back to root causes, support forensic investigations, and meet compliance requirements in regulated environments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-8\"><strong>When to Integrate AI Agents Into Your DevOps Stack<\/strong><\/h2>\n\n\n\n<p>Deciding when to adopt AI agents for AppSec depends on several factors \u2014 like hitting a critical volume of development activity, building up too much technical debt, or dealing with so much security noise that manual processes just can\u2019t keep up.<\/p>\n\n\n\n<p>Consider integrating AI agents when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your CI\/CD pipelines are slowing down due to frequent security-related build failures and long triage queues.<br>\n<\/li>\n\n\n\n<li>Your AppSec team cannot keep up with vulnerability validation, especially in fast-moving environments with high deployment velocity.<br>\n<\/li>\n\n\n\n<li>Developers are receiving too many false positives and need better context or auto-suggestions during PR reviews.<br>\n<\/li>\n\n\n\n<li>You have multilingual application stacks, and current tools don\u2019t scale across frameworks or languages.<br>\n<\/li>\n\n\n\n<li>Observability into security decision-making is lacking, and you need to trace which findings led to which remediations or decisions.<br>\n<\/li>\n<\/ul>\n\n\n\n<p><a href=\"https:\/\/checkmarx.com\/early-access-agentic-ai\/\">Checkmarx\u2019s multi-agent model<\/a> is purpose-built for these environments, offering intelligent coordination between agents to ensure they enhance rather than disrupt your DevOps rhythm.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-9\"><strong>What\u2019s Next: Evolving AppSec with Autonomous Agents<\/strong><\/h2>\n\n\n\n<p>The future of AppSec won&#8217;t be defined by a single breakthrough, but by how intelligently we orchestrate many of them. AI agents are here, and soon, we\u2019ll see context-aware systems that can understand business logic, weigh the tradeoffs of security decisions in real time, and continuously refine their recommendations based on live feedback from production environments.<\/p>\n\n\n\n<p>They\u2019ll draw from threat intelligence feeds, ingest supply chain signals, and learn from your own incident history to make smarter decisions the next time around.<\/p>\n\n\n\n<p>The real question isn\u2019t <em>if<\/em> AI agents will become part of your security posture. It\u2019s <em>how well prepared you are to trust them, govern them, and learn alongside them.<\/em> AppSec is a hybrid of human and machine, and the organizations that embrace this shift early will be the ones best positioned to defend, adapt, and thrive.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-10\"><strong>Ready to meet your first AI AppSec teammate?<\/strong><\/h2>\n\n\n\n<p>Learn how collaborative, autonomous security is reshaping the way teams build and secure modern applications in<a href=\"https:\/\/checkmarx.com\/blog\/multi-agent-networks-in-appsec-the-future-of-collaborative-autonomous-security\/\"> this deep dive on multi-agent networks in AppSec<\/a>.<\/p>\n\n\n<section class=\"section-block-info light-theme\">\n    <div class=\"main-wrapper block-info__wrapper\">\n        <div class=\"block-info center\">\n\t\t\t\n\t\t\t<h2 class=\"section-title article-anchor\" id=\"article-anchor-11\">Want to be Part of the Future of AppSec?<\/h2>\t\t\t<p class=\"section-description\">Register for early access to AI-powered, IDE-native AppSec agents shaping the future of enterprise security, from identification and analysis, to remediation of security vulnerabilities.<\/p>\n\t\t\t<div class=\"actions\">\n\t\t\t\t        <a href=\"https:\/\/checkmarx.com\/early-access-agentic-ai\/\" class=\"btn btn-2 btn-bg white demo\">Join Early Access<\/a>\n        \t\t\t\t\t\t\t<\/div>\n        <\/div>\n    <\/div>\n<\/section>","protected":false},"author":143,"featured_media":102567,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":true,"footnotes":""},"learn-cat":[853],"class_list":["post-102565","learn","type-learn","status-publish","has-post-thumbnail","hentry","learn-cat-appsec"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy<\/title>\n<meta name=\"description\" content=\"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy\" \/>\n<meta property=\"og:description\" content=\"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-25T16:06:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2033\" \/>\n\t<meta property=\"og:image:height\" content=\"1097\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\"},\"author\":{\"name\":\"Eran Kinsbruner\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/0e5df47a6fb9c1bc0e0b31ef6cfd41fa\"},\"headline\":\"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy\",\"datePublished\":\"2025-06-25T16:06:20+00:00\",\"dateModified\":\"2025-06-25T16:06:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\"},\"wordCount\":1515,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\",\"url\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\",\"name\":\"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp\",\"datePublished\":\"2025-06-25T16:06:20+00:00\",\"dateModified\":\"2025-06-25T16:06:21+00:00\",\"description\":\"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp\",\"width\":2033,\"height\":1097,\"caption\":\"AI agents collaborating in a software development environment to identify and remediate application security vulnerabilities across the SDLC.\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/0e5df47a6fb9c1bc0e0b31ef6cfd41fa\",\"name\":\"Eran Kinsbruner\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/05\/Eran-Kinsbruner-avatar-150x150.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/05\/Eran-Kinsbruner-avatar-150x150.jpg\",\"caption\":\"Eran Kinsbruner\"},\"description\":\"Enterprise Product Marketing Executive. Recognized thought leader, board advisor to stealth companies, researcher, inventor, and best-selling author of four books. Expertise in B2B SAAS, AI, observability, DevOps, and software quality.\",\"url\":\"https:\/\/checkmarx.com\/author\/erankinsbruner\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy","description":"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/","og_locale":"en_US","og_type":"article","og_title":"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy","og_description":"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.","og_url":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2025-06-25T16:06:21+00:00","og_image":[{"width":2033,"height":1097,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/"},"author":{"name":"Eran Kinsbruner","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/0e5df47a6fb9c1bc0e0b31ef6cfd41fa"},"headline":"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy","datePublished":"2025-06-25T16:06:20+00:00","dateModified":"2025-06-25T16:06:21+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/"},"wordCount":1515,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/","url":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/","name":"Leveraging AI Agents for AppSec: Scaling Security with Intelligent Autonomy","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp","datePublished":"2025-06-25T16:06:20+00:00","dateModified":"2025-06-25T16:06:21+00:00","description":"AI agents are transforming AppSec by autonomously detecting and fixing vulnerabilities without slowing development or adding headcount.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/learn\/appsec\/leveraging-ai-agents-for-appsec-scaling-security-with-intelligent-autonomy\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/06\/Leveraging-AI-Agents-for-AppSec.webp","width":2033,"height":1097,"caption":"AI agents collaborating in a software development environment to identify and remediate application security vulnerabilities across the SDLC."},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/0e5df47a6fb9c1bc0e0b31ef6cfd41fa","name":"Eran Kinsbruner","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/05\/Eran-Kinsbruner-avatar-150x150.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/05\/Eran-Kinsbruner-avatar-150x150.jpg","caption":"Eran Kinsbruner"},"description":"Enterprise Product Marketing Executive. Recognized thought leader, board advisor to stealth companies, researcher, inventor, and best-selling author of four books. Expertise in B2B SAAS, AI, observability, DevOps, and software quality.","url":"https:\/\/checkmarx.com\/author\/erankinsbruner\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn\/102565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/learn"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/143"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn\/102565\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/102567"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=102565"}],"wp:term":[{"taxonomy":"learn-cat","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn-cat?post=102565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}