{"id":106231,"date":"2025-12-24T17:06:49","date_gmt":"2025-12-24T15:06:49","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=106231"},"modified":"2025-12-29T20:24:37","modified_gmt":"2025-12-29T18:24:37","slug":"future-of-dast-why-ai-generated-code-demands-a-new-strategy","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/","title":{"rendered":"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0"},"content":{"rendered":"<p>AI is accelerating software development faster than any&nbsp;previous&nbsp;technological shift, embedding itself into the everyday developer workflow.&nbsp;As a result, both development speed and productivity&nbsp;have&nbsp;surged, but security teams are experiencing the opposite: more complexity, less visibility, and growing uncertainty about what code is&nbsp;<em>actually&nbsp;<\/em>running&nbsp;in production.&nbsp;<\/p>\n\n\n\n<p>This gap exposed&nbsp;that many organizations&nbsp;are&nbsp;still&nbsp;relying&nbsp;heavily on&nbsp;AppSec tools&nbsp;that predate AI-generated code.&nbsp;And&nbsp;they\u2019re&nbsp;quickly&nbsp;discovering,&nbsp;sometimes painfully,&nbsp;that these tools&nbsp;are&nbsp;struggling&nbsp;to make sense of&nbsp;(let alone protect)&nbsp;code created by AI.&nbsp;<\/p>\n\n\n\n<p>This convergence is driving an&nbsp;unexpected shift in application security: DAST is experiencing a renaissance.&nbsp;<\/p>\n\n\n\n<p>For years,&nbsp;DAST (Dynamic&nbsp;Application&nbsp;Security&nbsp;Testing)&nbsp;was dismissed as a&nbsp;\u201cnice to have,\u201d&nbsp;useful primarily for checking compliance boxes&nbsp;or&nbsp;just viewed as a pen testing tool.&nbsp;But as AI accelerates code creation and introduces&nbsp;new&nbsp;behaviors and attack surfaces, organizations are rediscovering&nbsp;that&nbsp;DAST is&nbsp;actually a&nbsp;critical pillar of AppSec.&nbsp;Only DAST can&nbsp;provide&nbsp;the broad deployment and meaningful security coverage needed&nbsp;in this new&nbsp;reality;&nbsp;coverage that static tools simply&nbsp;can&#8217;t&nbsp;deliver in an AI-driven world.&nbsp;<\/p>\n\n\n\n<p>This was the central theme of our recent webinar,&nbsp;<a href=\"https:\/\/checkmarx.com\/the-future-of-dast\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>The Future of DAST: Why AI-Generated Code Demands a New Strategy<\/em><\/a>, hosted by&nbsp;Checkmarx&nbsp;product leaders. Grounded in data from our annual&nbsp;<a href=\"https:\/\/checkmarx.com\/report-future-of-appsec-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">Future of AppSec Report<\/a>, the discussion explored&nbsp;some&nbsp;pressing questions:&nbsp;<strong>In a world where AI is reshaping how applications are built,&nbsp;what\u2019s&nbsp;working,&nbsp;what\u2019s&nbsp;broken, and why is DAST suddenly rising from the&nbsp;dead to become a&nbsp;crucial&nbsp;safeguard?<\/strong>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">Meet&nbsp;the Expert Panel&nbsp;<\/h2>\n\n\n\n<p>To explore these questions, we brought together three&nbsp;Checkmarx&nbsp;leaders uniquely positioned at the intersection of DAST innovation and AI-driven development:&nbsp;<\/p>\n\n\n\n<p><strong>Simon Bennetts<\/strong>,&nbsp;<em>ZAP Software Engineering Expert,&nbsp;Checkmarx&nbsp;and&nbsp;ZAP&nbsp;project leader&nbsp;and&nbsp;founder.<\/em>&nbsp;<\/p>\n\n\n\n<p><strong>Frank Emery<\/strong>,&nbsp;<em>Director of Product Management,&nbsp;Checkmarx<\/em>&nbsp;<\/p>\n\n\n\n<p>Moderated by&nbsp;<strong>Avi Hein<\/strong>,&nbsp;<em>Senior Product Marketing Manager at&nbsp;Checkmarx<\/em>, the conversation offered a candid look at the future of application security, and why DAST has become essential in the age of AI.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">The Hidden Reality&nbsp;of&nbsp;AI-Generated&nbsp;Code&nbsp;<\/h2>\n\n\n\n<p>The&nbsp;webinar&nbsp;opened with a simple poll:&nbsp;<em>What percentage of your organization&#8217;s application code is AI-generated?<\/em>&nbsp;The result was revealing,&nbsp;nearly half&nbsp;of respondents answered, \u201cWe don&#8217;t know.\u201d&nbsp;<\/p>\n\n\n\n<p>This sentiment aligns with findings from our&nbsp;<em>Future of AppSec Report<\/em>, which showed that while organizations recognize the&nbsp;risks of&nbsp;AI-generated code, they deploy it anyway. At the same time,&nbsp;however,&nbsp;the report revealed something surprising: DAST adoption is rising sharply.&nbsp;<\/p>\n\n\n\n<p><em>\u201c47% said they have DAST in place for 2025, up from 38% last year,\u201d<\/em>&nbsp;<strong>Avi&nbsp;<\/strong>noted.&nbsp;<em>\u201cThat&#8217;s nearly a 24% increase year over year.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>This growth signals a critical shift: organizations&nbsp;are increasingly&nbsp;recognizing&nbsp;that AI will be present in their code,&nbsp;but&nbsp;they\u2019re&nbsp;also admitting&nbsp;that&nbsp;their traditional security approaches&nbsp;aren\u2019t&nbsp;keeping&nbsp;up.&nbsp;The result?&nbsp;They\u2019re&nbsp;returning to runtime testing&nbsp;engines like DAST&nbsp;to close the gap.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">The DAST Renaissance&nbsp;<\/h2>\n\n\n\n<p>For the past decade, DAST lived in the margins of AppSec programs. It&nbsp;wasn\u2019t&nbsp;ignored entirely, but it&nbsp;wasn\u2019t&nbsp;central either. Many organizations ran it infrequently, before a major release or to satisfy a compliance requirement.&nbsp;<\/p>\n\n\n\n<p><strong>Simon&nbsp;<\/strong>described this evolution:&nbsp;<em>\u201cDAST started strong&#8230;But then as applications changed, DAST found it harder to explore these applications. Even authentication got&nbsp;really hard.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>As modern frameworks and authentication flows grew more complex, DAST struggled to keep up. Meanwhile, SAST surged in popularity because it was so simple to&nbsp;use. As&nbsp;<strong>Simon&nbsp;<\/strong>put it,&nbsp;<em>\u201cSAST was much easier to set up. You point it at your&nbsp;repo,&nbsp;and it can just go from there.\u201d<\/em>&nbsp;&nbsp;Suddenly, organizations&nbsp;were&nbsp;treating it as a choice:&nbsp;DAST or SAST.&nbsp;<\/p>\n\n\n\n<p>But the&nbsp;truth is that&nbsp;no single testing method provides complete coverage.&nbsp;<\/p>\n\n\n\n<p><strong>Simon&nbsp;<\/strong>emphasized:<em>&nbsp;\u201cI&#8217;ve&nbsp;never bought into the DAST or SAST thing.&nbsp;It&#8217;s&nbsp;much more important to combine these [two&nbsp;engines].&nbsp;There is no one view of security.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>In the AI era, DAST\u2019s unique strength&nbsp;in being to see&nbsp;what&nbsp;actually happens&nbsp;when an application runs&nbsp;matters more than ever.&nbsp;DAST reveals what\u2019s&nbsp;<em>\u201cgenuinely vulnerable, delivering fewer false positives and a better signal-to-noise ratio than static analysis alone.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">The AI Twist: Code That&nbsp;<em>Looks&nbsp;<\/em>Secure&nbsp;<\/h2>\n\n\n\n<p>One of the most compelling insights that&nbsp;emerged&nbsp;from the discussion was about AI-generated code. Many developers assume that if AI writes the code, it must be secure.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Frank&nbsp;<\/strong>explained why that assumption is dangerous:&nbsp;<em>\u201cPeople have this impression that AI-generated code is secure because the AI knows better. But what&nbsp;we\u2019re&nbsp;finding is AI writes code that looks very secure but still has a lot of gaps.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>And DAST plays a critical role in catching these hidden flaws.&nbsp;<\/p>\n\n\n\n<p><strong>Frank&nbsp;<\/strong>put it bluntly: \u201cDAST is acting as the police officer, confirming that all of the code that&#8217;s being written \u2013 especially by AI \u2013 is actually being written correctly.\u201d With decades of development and maturity behind it, DAST can catch vulnerabilities that other tools miss.&nbsp;<\/p>\n\n\n\n<p>This is why organizations relying heavily on GitHub Copilot, ChatGPT, and other generative tools are increasingly turning to DAST&nbsp;for protection.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">DAST Adoption Lagged,&nbsp;But&nbsp;It\u2019s&nbsp;Accelerating Now&nbsp;<\/h2>\n\n\n\n<p>Although DAST has always been powerful, its adoption has historically been slow.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>Simon&nbsp;<\/strong>summarized the challenge: \u201cDAST\u2026 is not as simple as SAST. You need a running system. You need to&nbsp;be able to&nbsp;authenticate. You need to&nbsp;be able to&nbsp;explore the application&#8230;Knowing how to&nbsp;tune [DAST] best for your applications is&nbsp;hard.\u201d&nbsp;<\/p>\n\n\n\n<p><strong>Frank&nbsp;<\/strong>agreed and added:&nbsp;<em>\u201cYou start to see onboarding and adoption issues&nbsp;when you create a bottleneck around how DAST is used. Historically, you have experts&#8230;in charge of getting DAST up and running and that fundamentally restricted how much it could be adopted.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>This complexity meant many organizations limited DAST usage to a handful of&nbsp;specialists,&nbsp;and you had to&nbsp;pick and choose&nbsp;what to test and how to test it. But modern DAST tools&nbsp;are&nbsp;focused on solving some of the usability challenges&nbsp;that more people within an organization can set up DAST.&nbsp;<\/p>\n\n\n\n<p>As&nbsp;<strong>Avi&nbsp;<\/strong>joked:&nbsp;<em>\u201cIf I can set it up, anybody can.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>It\u2019s&nbsp;this new&nbsp;focus on&nbsp;accessibility&nbsp;that&nbsp;is driving much of DAST\u2019s resurgence today.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\">Will AI Replace DAST? Not Even Close.&nbsp;<\/h2>\n\n\n\n<p>A major question during the session was whether agentic security systems might eventually replace DAST.&nbsp;<\/p>\n\n\n\n<p><strong>Simon\u2019s&nbsp;<\/strong>answer was unequivocal:&nbsp;<em>\u201cI don&#8217;t see agentic systems as being a threat to DAST and they won&#8217;t replace DAST, but I do see that DAST will feed into agentic&nbsp;systems,&nbsp;and we\u2019ll also get LLMs configuring these systems.\u201d&nbsp;<\/em>&nbsp;He explained that&nbsp;there will be a shift in the marketplace, but&nbsp;DAST&nbsp;remains&nbsp;unmatched&nbsp;and it&nbsp;won\u2019t&nbsp;be going anywhere any time soon.&nbsp;<\/p>\n\n\n\n<p><strong>Frank&nbsp;<\/strong>echoed this view:&nbsp;<em>\u201cLLMs are not going to get rid of DAST at all.&nbsp;It\u2019s&nbsp;just a more expensive way to solve a problem, but they will get rid of a lot of the manual&nbsp;stuff.\u201d<\/em>&nbsp;He sees LLMs playing a role in helping to configure and scale DAST. It will look different than how people are envisioning it.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The&nbsp;consensus&nbsp;was that&nbsp;AI&nbsp;will&nbsp;be&nbsp;leveraged&nbsp;to&nbsp;enhance DAST&nbsp;by&nbsp;automating configuration, improving coverage, and reducing human effort&nbsp;\u2013&nbsp;while DAST continues to anchor runtime security.&nbsp;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"936\" height=\"423\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-6.png\" alt=\"Future of DAST Webinar - live screen for panel\" class=\"wp-image-106233\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-6.png 936w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-6-300x136.png 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-6-768x347.png 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/image-6-400x181.png 400w\" sizes=\"(max-width: 936px) 100vw, 936px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\">Testing AI-Powered Apps&nbsp;<\/h2>\n\n\n\n<p>As organizations deploy more AI-powered applications, a critical question&nbsp;emerged&nbsp;during the session: How do we test the security of AI-powered&nbsp;AppSec&nbsp;engines?&nbsp;<\/p>\n\n\n\n<p><strong>Frank&nbsp;<\/strong>admitted that AI introduces&nbsp;the need for entirely new testing requirements that go beyond traditional DAST capabilities:&nbsp;<\/p>\n\n\n\n<p>\u201cThe&nbsp;end goal&nbsp;[of trying to secure your application and trying to find vulnerabilities]&nbsp;hasn\u2019t&nbsp;changed.&nbsp;But, as&nbsp;new technologies&nbsp;come out,&nbsp;likely the&nbsp;engines you&nbsp;involve&nbsp;and how you orchestrate them together will look a little bit different. And&nbsp;that\u2019s&nbsp;where some of the value of more modern DAST tools is going to come&nbsp;in.\u201d&nbsp;<\/p>\n\n\n\n<p>But eventually we will need AI&nbsp;solutions&nbsp;that can secure themselves.&nbsp;<strong>Frank&nbsp;<\/strong>discussed the broader vision of self-securing applications, which he broke into four essential steps:&nbsp;identifying&nbsp;vulnerabilities, triaging them, fixing them, and verifying the fix.&nbsp;<\/p>\n\n\n\n<p><em>\u201cPeople think this idea&nbsp;of a self-securing application&nbsp;is very Star Trek,\u201d&nbsp;<\/em><strong>Frank&nbsp;<\/strong>said.<em>&nbsp;\u201cI&#8217;m&nbsp;a huge believer. I think&nbsp;we&#8217;re&nbsp;actually a&nbsp;lot closer than people realize.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>DAST already plays&nbsp;a central role&nbsp;in three of these four steps&nbsp;\u2013&nbsp;it&#8217;s&nbsp;the foundation that&nbsp;will&nbsp;ultimately&nbsp;make&nbsp;self-securing applications possible.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-8\">Why Siloed Security Tools&nbsp;Are&nbsp;Failing&nbsp;<\/h2>\n\n\n\n<p>The session concluded with a discussion about fragmented AppSec stacks \u2013 having separate tools for SAST, SCA, and DAST, with each producing isolated reports with no correlation between findings.&nbsp;<\/p>\n\n\n\n<p>When asked if this fragmentation is truly as problematic as it sounds,&nbsp;<strong>Simon&nbsp;<\/strong>didn&#8217;t&nbsp;hesitate:&nbsp;<em>\u201cNo, it is as bad as&nbsp;you&#8217;re&nbsp;making it sound.&nbsp;It&#8217;s&nbsp;generally horrible.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>Issues fall through the&nbsp;cracks,&nbsp;teams lose visibility, and developers drown in noise.&nbsp;<strong>Frank&nbsp;<\/strong>connected this directly to the AI acceleration challenge:&nbsp;<em>\u201cIf you&#8217;re generating code ten times faster and your security team isn&#8217;t getting ten times faster, then you&#8217;re going to have to make difficult decisions, and that&#8217;s where risk emerges.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>The solution lies in unified AppSec platforms like&nbsp;Checkmarx&nbsp;One, which&nbsp;consolidate&nbsp;findings across all testing engines, correlate signals to reduce noise, and deliver security feedback directly into developer workflows&nbsp;\u2013&nbsp;at the speed AI demands.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-9\">What Will 2026 Look Like?&nbsp;<\/h2>\n\n\n\n<p>Everyone&nbsp;agrees that&nbsp;AI-generated applications will become more standardized, making DAST more effective over time:&nbsp;<br>According to&nbsp;<strong>Frank<\/strong>, \u201c<em>with LLM-generated apps,&nbsp;there\u2019s&nbsp;more standardization\u2026 The bulk will coalesce around standard ways of doing things, and that will make our jobs easier.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<p>He also&nbsp;predicts growing reliance on DAST as the primary method for validating AI-generated code:&nbsp;<em>\u201cPeople are going to rely on DAST progressively more as the way to secure AI-generated code.&nbsp;It\u2019s&nbsp;too easy a solution to the problems&nbsp;we\u2019re&nbsp;seeing for it not to become standardized.\u201d<\/em>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-10\">The Takeaway: DAST Is No Longer Optional&nbsp;<\/h2>\n\n\n\n<p>Across the entire discussion, the message was unmistakable:&nbsp;<strong>DAST has shifted from a compliance checkbox to a mission-critical security control for the AI era.<\/strong>&nbsp;<\/p>\n\n\n\n<p>As AI accelerates development&nbsp;and introduces new runtime behaviors, only DAST can reveal what is truly exploitable in the live application. Organizations that treat DAST as optional will struggle to keep up with the pace and unpredictability of AI-driven development.&nbsp;<\/p>\n\n\n\n<p>Those that embrace it&nbsp;and integrate it into unified AppSec workflows&nbsp;will be best positioned to secure the next generation of software.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-11\">Find Out More\u00a0About DAST\u00a0<\/h2>\n\n\n\n<p>Want&nbsp;to&nbsp;see&nbsp;the future of DAST?&nbsp;&nbsp;<a href=\"https:\/\/checkmarx.com\/request-a-demo\/\" target=\"_blank\" rel=\"noreferrer noopener\">Contact us for a demo<\/a>&nbsp;and&nbsp;a discussion&nbsp;about&nbsp;the future&nbsp;\u2013&nbsp;and&nbsp;present&nbsp;\u2013&nbsp;of DAST&nbsp;and why&nbsp;DAST is&nbsp;so&nbsp;critical&nbsp;for the AI era.&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>AI is accelerating software development faster than any&nbsp;previous&nbsp;technological shift, embedding itself into the everyday developer workflow.&nbsp;As a result, both development speed and productivity&nbsp;have&nbsp;surged, but security teams are experiencing the opposite: more complexity, less visibility, and growing uncertainty about what code is&nbsp;actually&nbsp;running&nbsp;in production.&nbsp; This gap exposed&nbsp;that many organizations&nbsp;are&nbsp;still&nbsp;relying&nbsp;heavily on&nbsp;AppSec tools&nbsp;that predate AI-generated code.&nbsp;And&nbsp;they\u2019re&nbsp;quickly&nbsp;discovering,&nbsp;sometimes painfully,&nbsp;that these tools&nbsp;are&nbsp;struggling&nbsp;to [&hellip;]<\/p>\n","protected":false},"author":84,"featured_media":106232,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[85,84,1424,1283,1292,1282],"tags":[1429,87,1470,479],"class_list":["post-106231","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security-trends","category-blog","category-checkmarx-one","category-checkmarx-product-use-cases-guides","category-dast","category-devsecops-integration-automation","tag-ai-generated-code-2","tag-appsec","tag-dast","tag-webinar"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0<\/title>\n<meta name=\"description\" content=\"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0\" \/>\n<meta property=\"og:description\" content=\"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-24T15:06:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-29T18:24:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Avi Hein\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Avi Hein\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\"},\"author\":{\"name\":\"Avi Hein\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79\"},\"headline\":\"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0\",\"datePublished\":\"2025-12-24T15:06:49+00:00\",\"dateModified\":\"2025-12-29T18:24:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\"},\"wordCount\":2168,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp\",\"keywords\":[\"AI generated code\",\"AppSec\",\"dast\",\"Webinar\"],\"articleSection\":[\"Application Security Trends &amp; Insights\",\"Blog\",\"Checkmarx One\",\"Checkmarx Product News, Use Cases &amp; Guides\",\"DAST\",\"DevSecOps Integration &amp; Automation\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\",\"name\":\"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp\",\"datePublished\":\"2025-12-24T15:06:49+00:00\",\"dateModified\":\"2025-12-29T18:24:37+00:00\",\"description\":\"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp\",\"width\":2560,\"height\":1280},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79\",\"name\":\"Avi Hein\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png\",\"caption\":\"Avi Hein\"},\"url\":\"https:\/\/checkmarx.com\/author\/avihein\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0","description":"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/","og_locale":"en_US","og_type":"article","og_title":"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0","og_description":"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future","og_url":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2025-12-24T15:06:49+00:00","article_modified_time":"2025-12-29T18:24:37+00:00","og_image":[{"width":2560,"height":1280,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp","type":"image\/webp"}],"author":"Avi Hein","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Avi Hein","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/"},"author":{"name":"Avi Hein","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79"},"headline":"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0","datePublished":"2025-12-24T15:06:49+00:00","dateModified":"2025-12-29T18:24:37+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/"},"wordCount":2168,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp","keywords":["AI generated code","AppSec","dast","Webinar"],"articleSection":["Application Security Trends &amp; Insights","Blog","Checkmarx One","Checkmarx Product News, Use Cases &amp; Guides","DAST","DevSecOps Integration &amp; Automation"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/","url":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/","name":"Future of DAST: Why AI-Generated Code Demands a New Strategy\u00a0","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp","datePublished":"2025-12-24T15:06:49+00:00","dateModified":"2025-12-29T18:24:37+00:00","description":"AI-generated code is reshaping AppSec. Learn why DAST is a critical security control and what experts say about its role in the future","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/future-of-dast-why-ai-generated-code-demands-a-new-strategy\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/12\/Blog-Banner-1.webp","width":2560,"height":1280},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79","name":"Avi Hein","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png","caption":"Avi Hein"},"url":"https:\/\/checkmarx.com\/author\/avihein\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/106231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/84"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=106231"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/106231\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/106232"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=106231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=106231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=106231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}