{"id":107564,"date":"2026-03-24T17:09:32","date_gmt":"2026-03-24T15:09:32","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=107564"},"modified":"2026-03-24T17:11:27","modified_gmt":"2026-03-24T15:11:27","slug":"checkmarx-dast-for-the-ai-coding-era","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/","title":{"rendered":"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed"},"content":{"rendered":"<p>DAST is suddenly on everyone\u2019s mind \u2013 and for good reason.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Most DAST tools were designed for a world where release cycles were measured in&nbsp;months&nbsp;and penetration testing happened once a year. That model made sense when development moved slowly enough for episodic security reviews to provide meaningful coverage.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Then AI accelerated everything, with&nbsp;AI coding assistants compressing&nbsp;weeks of work into hours.&nbsp;<\/p>\n\n\n\n<p>The gap between how fast applications&nbsp;are&nbsp;being built and how quickly they can be validated is exactly&nbsp;where risk lives. Runtime validation has moved from a nice-to-have to a foundational part of any serious application security program.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The question is no longer whether to implement DAST. It is whether your DAST can&nbsp;keep pace with how&nbsp;fast&nbsp;your teams are building.&nbsp;<\/p>\n\n\n\n<p>Checkmarx&nbsp;has been investing&nbsp;and&nbsp;adapting in&nbsp;runtime security&nbsp;<a href=\"https:\/\/checkmarx.com\/blog\/shift-everywhere-with-checkmarx-one-and-dast\/\" target=\"_blank\" rel=\"noreferrer noopener\">since 2023,<\/a>&nbsp;well before AI-driven development made it&nbsp;a&nbsp;market-wide&nbsp;priority.&nbsp;So,&nbsp;when AI&nbsp;fundamentally&nbsp;changed&nbsp;the pace of software development,&nbsp;we&nbsp;didn\u2019t&nbsp;need to retrofit our approach&nbsp;\u2013 because we&nbsp;were already&nbsp;building&nbsp;for this moment.&nbsp;<\/p>\n\n\n\n<p>The result is the next generation of&nbsp;Checkmarx&nbsp;DAST: runtime security designed to move at AI speed.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">\n<strong>Why Traditional DAST&nbsp;Can\u2019t&nbsp;Keep Pace<\/strong>&nbsp;<\/h2>\n\n\n\n<p>Legacy DAST often depends on heavy&nbsp;<strong>infrastructure&nbsp;setup<\/strong>. Scanning internal applications can require&nbsp;firewall&nbsp;changes, VPN access, security exceptions, or container deployments. These dependencies introduce approval cycles and coordination overhead that simply&nbsp;don\u2019t&nbsp;align with applications being built in days or hours.&nbsp;&nbsp;That model may work for annual testing, but it breaks down completely when security needs to run continuously in your CI\/CD pipeline.&nbsp;<\/p>\n\n\n\n<p><strong>Configuration&nbsp;<\/strong>adds another layer of friction. Authentication scripting, scan tuning, and policy setup frequently&nbsp;require specialized&nbsp;expertise. When onboarding takes longer than development itself, coverage gaps become inevitable.&nbsp;<\/p>\n\n\n\n<p>Even when scanning runs successfully,&nbsp;<strong>context<\/strong>&nbsp;is often fragmented. If SAST and DAST operate in separate systems, teams must manually reconcile findings, deduplicate issues, and correlate risk. That overhead slows remediation and reduces the practical value of runtime testing.&nbsp;<\/p>\n\n\n\n<p>In short, traditional DAST&nbsp;wasn\u2019t&nbsp;built for continuous, developer-driven workflows. It was built for episodic&nbsp;pen&nbsp;testing. And in the AI era,&nbsp;this&nbsp;security creates exposure.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">\n<strong>Runtime Validation Is Now Foundational<\/strong>&nbsp;<\/h2>\n\n\n\n<p>Runtime testing has become a core&nbsp;component&nbsp;of modern application security programs.&nbsp;<\/p>\n\n\n\n<p>In fact, according to the&nbsp;<a href=\"https:\/\/checkmarx.com\/report-future-of-appsec-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\"><em>Future of AppSec<\/em><\/a>&nbsp;report, DAST adoption increased 24% year over year, with 47% of organizations now deploying DAST&nbsp;\u2013&nbsp;up from 38% the previous year. The reason is clear:&nbsp;<a href=\"https:\/\/checkmarx.com\/blog\/unifying-sast-and-dast-the-key-to-fostering-fearless-innovation\/\" target=\"_blank\" rel=\"noreferrer noopener\">static analysis alone&nbsp;isn\u2019t&nbsp;enough to secure<\/a>&nbsp;dynamic, API-driven, AI-assisted applications.&nbsp;<\/p>\n\n\n\n<p>Many vulnerabilities, such as&nbsp;business logic flaws, authentication weaknesses, and configuration errors only&nbsp;emerge&nbsp;when applications are running.&nbsp;So,&nbsp;validating&nbsp;behavior in live environments is no longer optional;&nbsp;it\u2019s&nbsp;essential.&nbsp;<\/p>\n\n\n\n<p>The conversation has shifted from&nbsp;<em>whether<\/em>&nbsp;to implement DAST to&nbsp;<em>how<\/em>&nbsp;to implement it effectively&nbsp;without slowing development.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">\n<strong>Why Runtime Validation Matters in the AI Era<\/strong>&nbsp;<\/h2>\n\n\n\n<p>AI-generated code increases productivity,&nbsp;but it also introduces&nbsp;new&nbsp;risks. Large language models (LLMs)&nbsp;generate functional code, yet they lack full business context and architectural awareness. At higher velocity, human review becomes more constrained.&nbsp;<\/p>\n\n\n\n<p>SAST&nbsp;remains&nbsp;critical for&nbsp;identifying&nbsp;vulnerabilities in source code before deployment. But it does not verify how an application behaves once it is running,&nbsp;especially in environments with complex authentication, APIs, client-side logic, and layered infrastructure.&nbsp;<\/p>\n\n\n\n<p>DAST provides&nbsp;that validation.&nbsp;<\/p>\n\n\n\n<p>By simulating real-world attacker behavior against live applications, it&nbsp;identifies&nbsp;issues that only appear under&nbsp;real operating&nbsp;conditions.&nbsp;<\/p>\n\n\n\n<p>Static analysis shows you what the code is. Runtime validation&nbsp;and DAST&nbsp;show you how it behaves. <strong>Modern application security requires both.<\/strong>&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">\n<strong>How&nbsp;Does&nbsp;Checkmarx&nbsp;DAST Solve This?<\/strong>&nbsp;<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Complete AppSec in One Platform<\/strong><\/h3>\n\n\n\n<p>Checkmarx&nbsp;DAST is built natively within&nbsp;Checkmarx&nbsp;One, delivering unified SAST and DAST findings&nbsp;in&nbsp;a single&nbsp;platform.&nbsp;DAST vulnerabilities&nbsp;are incorporated into&nbsp;a unified&nbsp;risk scoring, enabling faster triage and&nbsp;eliminating&nbsp;duplicate effort.&nbsp;<\/p>\n\n\n\n<p>It is true platform integration&nbsp;with&nbsp;shared context from code to runtime.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Live API scanning further strengthens coverage. REST, SOAP, and\u00a0gRPC\u00a0endpoints are tested dynamically, and APIs discovered by both SAST and DAST are\u00a0consolidated\u00a0into one unified inventory.\u00a0<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Production-Ready in Minutes<\/h3>\n\n\n\n<p>Traditional DAST adoption has been slowed by infrastructure and configuration barriers.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Checkmarx&nbsp;DAST removes them.&nbsp;<\/p>\n\n\n\n<p>Teams can begin scanning&nbsp;immediately&nbsp;without complex network reconfiguration or custom authentication scripting through:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Pre-configured tunneling<\/strong>&nbsp;for secure internal application scanning<\/li>\n\n\n\n<li>\n<strong>Advanced authentication support<\/strong>&nbsp;with guided setup and MFA validation<\/li>\n\n\n\n<li>\n<strong>Pre-built templates<\/strong>&nbsp;that simplify configuration&nbsp;<\/li>\n\n\n\n<li>\n<strong>Direct CI\/CD integration&nbsp;<\/strong>for continuous testing<\/li>\n<\/ul>\n\n\n\n<p>What once required weeks&nbsp;to set up&nbsp;now&nbsp;can be done in&nbsp;minutes.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\n<strong>Designed for Developer Workflows<\/strong>&nbsp;<\/h3>\n\n\n\n<p>With legacy tools, teams file networking tickets, wait for authentication scripts, and manually reconcile findings before deployment.&nbsp;<\/p>\n\n\n\n<p>With&nbsp;Checkmarx&nbsp;DAST, scanning is configured quickly, authentication is&nbsp;validated&nbsp;through guided workflows, and SAST and DAST findings appear together with correlated risk scoring. Developers receive actionable feedback directly within their pipeline and deploy confidently&nbsp;without introducing bottlenecks.&nbsp;<\/p>\n\n\n\n<p>Security moves with development, not against it.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\n<strong>Runtime Validation You Can Trust<\/strong>&nbsp;<\/h3>\n\n\n\n<p>Checkmarx&nbsp;DAST validates live applications and uncovers vulnerabilities that only&nbsp;emerge&nbsp;at runtime. Because it&nbsp;operates&nbsp;within a unified platform, findings are correlated with SAST results to reduce false positives and improve prioritization.&nbsp;<\/p>\n\n\n\n<p>The result is&nbsp;accurate,&nbsp;actionable&nbsp;runtime security&nbsp;without added friction.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\"><strong>Here\u2019s&nbsp;What&nbsp;Makes&nbsp;Checkmarx&nbsp;DAST Different<\/strong><\/h2>\n\n\n\n<p>Checkmarx&nbsp;DAST stands apart because it is:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<strong>Integrated seamlessl<\/strong>y&nbsp;within&nbsp;Checkmarx&nbsp;One,&nbsp;not&nbsp;acquired&nbsp;technology stitched together&nbsp;&nbsp;<\/li>\n\n\n\n<li>\n<strong>Infrastructure-light,<\/strong>&nbsp;eliminating&nbsp;complex agent and network requirements<\/li>\n\n\n\n<li>\n<strong>Comprehensive in scope<\/strong>, covering full web applications and APIs<\/li>\n\n\n\n<li>\n<strong>Enterprise-grade<\/strong>, while&nbsp;remaining&nbsp;accessible to development teams<\/li>\n<\/ul>\n\n\n\n<p>It is built on the proven ZAP foundation with commercial-grade enhancements.&nbsp;The&nbsp;<a href=\"https:\/\/checkmarx.com\/press-releases\/checkmarx-joins-forces-with-zap-to-supercharge-dynamic-application-security-testing-dast-for-the-enterprise-and-enhance-community-growth\/\" target=\"_blank\" rel=\"noreferrer noopener\">Checkmarx-ZAP collaboration<\/a>&nbsp;enables&nbsp;open-source innovation&nbsp;alongside&nbsp;enterprise reliability and scalability.&nbsp;&nbsp;<\/p>\n\n\n\n<p>In fact, ZAP project leaders Simon Bennetts, Rick Mitchell, and Ricardo Pereira joined&nbsp;Checkmarx&nbsp;to help build the next generation of our enterprise-grade DAST offering, while continuing to invest in the open-source ZAP project and grow its global community.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\">\n<strong>Getting Started<\/strong>&nbsp;<\/h2>\n\n\n\n<p><strong>Existing&nbsp;Checkmarx&nbsp;customers<\/strong>: Professional and Enterprise plans include DAST. Essentials customers can add DAST to their existing subscription.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>New customers<\/strong>: See the unified&nbsp;Checkmarx&nbsp;One platform in action and discover how DAST integrates seamlessly with SAST for complete code-to-runtime security.&nbsp;<\/p>\n\n\n\n<p>You can also&nbsp;tune into our&nbsp;DAST&nbsp;webinar&nbsp;to see it in action&nbsp;<a href=\"https:\/\/checkmarx.com\/the-future-of-dast\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\">\n<strong>What\u2019s Next<\/strong>&nbsp;<\/h2>\n\n\n\n<p>The shift is already underway.&nbsp;According to&nbsp;the&nbsp;Future of&nbsp;AppSec report,&nbsp;DAST&nbsp;adoption grew&nbsp;24% year over year&nbsp;\u2013&nbsp;not because security teams suddenly discovered runtime testing, but because the old model of annual pen tests and periodic scans no longer provide meaningful coverage. Teams building with AI-generated&nbsp;codeneed&nbsp;security that moves on the same timeline.&nbsp;<\/p>\n\n\n\n<p>Checkmarx&nbsp;DAST is built for that reality: unified&nbsp;with SAST&nbsp;on&nbsp;a single platform, deployable in minutes, and designed to work within developer workflows rather than around them.&nbsp;<\/p>\n\n\n\n<p>If you are an existing&nbsp;Checkmarx&nbsp;customer, DAST is already included in Professional and Enterprise plans. Essentials customers can add it to their current&nbsp;subscription&nbsp;and new&nbsp;customers can&nbsp;see it in action at our&nbsp;upcoming&nbsp;webinar.&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>The question is no longer whether to implement DAST. It is whether your DAST can keep pace with how fast your teams are building.<\/p>\n","protected":false},"author":84,"featured_media":107567,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1284,84,1292],"tags":[1272,87,1470],"class_list":["post-107564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-llm-tools-in-application-security","category-blog","category-dast","tag-agentic-ai","tag-appsec","tag-dast"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed<\/title>\n<meta name=\"description\" content=\"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed\" \/>\n<meta property=\"og:description\" content=\"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-24T15:09:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-24T15:11:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_-1024x512.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Avi Hein\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Avi Hein\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\"},\"author\":{\"name\":\"Avi Hein\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79\"},\"headline\":\"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed\",\"datePublished\":\"2026-03-24T15:09:32+00:00\",\"dateModified\":\"2026-03-24T15:11:27+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\"},\"wordCount\":1404,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp\",\"keywords\":[\"Agentic AI\",\"AppSec\",\"dast\"],\"articleSection\":[\"AI &amp; LLM Tools in Application Security\",\"Blog\",\"DAST\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\",\"name\":\"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp\",\"datePublished\":\"2026-03-24T15:09:32+00:00\",\"dateModified\":\"2026-03-24T15:11:27+00:00\",\"description\":\"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp\",\"width\":2560,\"height\":1280,\"caption\":\"Agentic AI DAST\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79\",\"name\":\"Avi Hein\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png\",\"caption\":\"Avi Hein\"},\"url\":\"https:\/\/checkmarx.com\/author\/avihein\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed","description":"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/","og_locale":"en_US","og_type":"article","og_title":"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed","og_description":"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.","og_url":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2026-03-24T15:09:32+00:00","article_modified_time":"2026-03-24T15:11:27+00:00","og_image":[{"width":1024,"height":512,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_-1024x512.webp","type":"image\/webp"}],"author":"Avi Hein","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Avi Hein","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/"},"author":{"name":"Avi Hein","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79"},"headline":"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed","datePublished":"2026-03-24T15:09:32+00:00","dateModified":"2026-03-24T15:11:27+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/"},"wordCount":1404,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp","keywords":["Agentic AI","AppSec","dast"],"articleSection":["AI &amp; LLM Tools in Application Security","Blog","DAST"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/","url":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/","name":"Checkmarx DAST for the AI Coding Era: Runtime Security at Machine Speed","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp","datePublished":"2026-03-24T15:09:32+00:00","dateModified":"2026-03-24T15:11:27+00:00","description":"The question is not whether or not to implement DAST. It is whether your DAST can\u00a0keep pace with how\u00a0fast\u00a0your teams are building.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-dast-for-the-ai-coding-era\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2026\/03\/Blog-Banner-_3_.webp","width":2560,"height":1280,"caption":"Agentic AI DAST"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/3546917fa0246ce4d997275a745acd79","name":"Avi Hein","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_84.png","caption":"Avi Hein"},"url":"https:\/\/checkmarx.com\/author\/avihein\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/107564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/84"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=107564"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/107564\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/107567"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=107564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=107564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=107564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}