{"id":96882,"date":"2024-07-31T13:04:45","date_gmt":"2024-07-31T13:04:45","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?post_type=learn&#038;p=96882"},"modified":"2026-04-15T22:35:08","modified_gmt":"2026-04-15T20:35:08","slug":"the-complete-guide-to-ai-application-security-testing","status":"publish","type":"learn","link":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/","title":{"rendered":"AI Security Testing: Safeguarding DevSecOps in the Age of GenAI and LLMs"},"content":{"rendered":"<blockquote>\n<p><b>Summary: <\/b><span style=\"font-weight: 400;\">The use of LLMs and other AI advances have changed the way developers generate code and deploy applications, but they don\u2019t come without risk. This article is a deep-dive into the <\/span><span style=\"font-weight: 400;\">application of AI in cyber security<\/span><span style=\"font-weight: 400;\"> to support DevSecOps teams in leveraging GenAI and LLMs, while reducing the growing risk landscape associated with AI.\u00a0<\/span><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">application of AI in cyber security<\/span><span style=\"font-weight: 400;\"> is a huge topic, and one that\u2019s changing all the time. In this guide &#8211; we will look specifically at artificially intelligent (<\/span><span style=\"font-weight: 400;\">AI) application security <\/span><span style=\"font-weight: 400;\">solutions, and click down into areas such as <\/span><span style=\"font-weight: 400;\">AI-driven software composition analysis<\/span><span style=\"font-weight: 400;\">, the <\/span><span style=\"font-weight: 400;\">application of AI in SAST (Static Application Security Testing)<\/span><span style=\"font-weight: 400;\">, and the <\/span><span style=\"font-weight: 400;\">application of AI in security<\/span><span style=\"font-weight: 400;\"> where it relates to generating and deploying more secure code at every stage of the Software Development Lifecycle (SLDC).\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Going deeper into practical strategies and products, this guide will also discuss a variety of tools that leverage AI, including SAST tools, AI tools for IaC (Infrastructure as Code) and Checkmarx features that provide SCA (Software Composition Analysis) and describe how they can reduce risk while supporting DevOps and AppSec teams in keeping up with the pace of development.\u00a0<\/span><\/p>\n<div id=\"attachment_96886\" style=\"width: 686px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-96886\" class=\"wp-image-96886 size-full\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-4.jpg\" alt=\"Chart of AI in application security CISO survey results\" width=\"676\" height=\"394\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-4.jpg 676w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-4-300x175.jpg 300w\" sizes=\"(max-width: 676px) 100vw, 676px\" \/><p id=\"caption-attachment-96886\" class=\"wp-caption-text\">&#8220;2024 Appsec Executive Survey: <br>What is your level of concern about security threats stemming from developers using AI code generation tools to write code?&#8221;<\/p><\/div>\n<p><span style=\"font-weight: 400;\">If you\u2019ve been asking yourself, \u2018What are the risks of the growing use of AI in application security?\u2019, \u2018Where does GenAI come into the picture?\u2019, and \u2018How can teams leverage AI without adding risk factors to their organizations?\u2019 you\u2019re in the right place!\u00a0\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-1\">\n<span style=\"font-weight: 400;\">The Rise in the <\/span><span style=\"font-weight: 400;\">Application of AI in Cybersecurity<\/span>\n<\/h2>\n<p><span style=\"font-weight: 400;\">The truth is, the <\/span><span style=\"font-weight: 400;\">application of AI in security<\/span><span style=\"font-weight: 400;\"> is nothing new. The global market for AI in cyber security is <\/span><a href=\"https:\/\/www.acumenresearchandconsulting.com\/artificial-intelligence-in-cybersecurity-market#:~:text=The%20Global%20Artificial%20Intelligence%20(AI,USD%20133.8%20Billion%20by%202030.\"><span style=\"font-weight: 400;\">predicted to hit 133.8 billion by 2030.<\/span><\/a><span style=\"font-weight: 400;\"> AI tools enable cyber security professionals to free up time from being weighed down by manual tasks, and work in a smarter and more efficient way to face the growing number of threats organizations are facing. AI can already take on roles across varied areas of cyber security such as threat detection, data analysis, automating manual tasks, alerts, reporting and more.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">More recently, GenAI, a subset of AI that involves creating new content such as images, text or code using complex algorithms and models, has stolen many a headline. This branch of AI that focuses on creating original and creative outputs &#8211; rather than simply analyzing or classifying existing data, is behind the Large Language Models (LLMs) that are increasingly prevalent, including ChatGPT, Bard, Copilot, and more. LLMs for developers focus on generating code, making it quicker and easier for Dev teams to do their work.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, as development teams increase their use of AI to speed up their work, as well as create their own LLMs to enhance their products, security concerns need to be front and center. Organizations should take some time to consider how they can support application security teams with making security a core part of both application development and deployment.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Already, <\/span><a href=\"https:\/\/survey.stackoverflow.co\/2023\/\"><span style=\"font-weight: 400;\">82.5% of developers<\/span><\/a><span style=\"font-weight: 400;\"> are using GenAI to write code, and 42% say they trust the output of LLMs, with just 31% holding back and saying they are unsure. 77% of respondents are happy to say that they like the experience of using AI tools, and up to 80% of developers recognize that their development workflow will look extremely different 12 months from now &#8211; as a direct result of AI tools. There\u2019s no doubt that AI-based code generation is the future, from writing code itself, to getting feedback and troubleshooting during development.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But before rushing into a new way of working, it\u2019s critical for businesses to understand the risks. How does AI work, how can LLMs do so much so quickly, and what threats should security teams be aware of before giving developers the freedom to use AI in their day-to-day work?\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-2\"><span style=\"font-weight: 400;\">Understanding the Risks of GenAI for Development Teams\u00a0<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">To help fully grasp the risks involved in using LLMs, let\u2019s look to the <\/span><a href=\"https:\/\/genai.owasp.org\/\"><span style=\"font-weight: 400;\">OWASP Top 10 for LLMs<\/span><\/a><span style=\"font-weight: 400;\">, a list of the most critical vulnerabilities found in applications that are utilizing LLMs. This list is a practical support to guide developers and security professionals in understanding the threat landscape, whether they are leveraging AI and LLMs in their work, or whether they are building LLMs as part of their product or service. It categorizes the challenges businesses will face to help them to implement the right security tools to close gaps in visibility and control, and to enable AppSec velocity while securing the new ways of working.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">1. Prompt injection<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Threat actors can manipulate an LLM using unique prompts that make the LLM execute malicious intentions. This can be done directly, usually called jailbreaking &#8211; where the underlying system prompt is overwritten or exposed, which means the attacker can access data or backend systems.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-96884 size-full\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-1-1.jpg\" alt=\"Stat highlighting AI security testing concerns in AppSec through Prompt Injections\" width=\"672\" height=\"162\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-1-1.jpg 672w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-1-1-300x72.jpg 300w\" sizes=\"(max-width: 672px) 100vw, 672px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">It can also happen indirectly, when an LLM accepts input from other sources, which could be controlled by an attacker, and may not even be recognizable to the human engaging with the LLM. Prompt injection can lead to data leakage, social engineering attacks, and more.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">2. Insecure output handling<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">LLM-generated content is controlled by prompts, which means there can be challenges in validating information, sanitizing data, and even with threat actors injecting malicious content before it\u2019s passed downstream. This can result in remote code execution on backend systems, privilege escalation, or CSS and CSRF in web browsers. In some cases, third party plugins may not validate LLM input at all, or the LLM has privileges which it does not need, making this threat even more of a risk.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">3. Training data poisoning<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">All LLMs use raw data, or training data, to learn what they need to know to generate the right outputs, and also use fine tuning data to narrow down an LLMs remit. Using neural networks, LLMs learn to find patterns and create outputs based on their training data. However, if attackers manipulate the original data, the model can be compromised or contain vulnerabilities. Users may automatically trust an LLM, when actually it is surfacing malicious or incorrect information. Training data poisoning is a kind of integrity attack, which is more prevalent when a model is training from external data sources where the LLM owners do not have control over the data.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">4. Model denial of service<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Similar to a traditional Denial of Service attack, where a target is overwhelmed by an exceptionally high amount of traffic, a model denial of service attack is when an attacker consumes enough resources from an LLM to reduce service quality or result in a high level of expense for the owner. One approach is to manipulate the context window &#8211; which is the maximum length of the text that an LLM can work with, and tightly linked to the complexity an LLM can manage. Attackers can attempt a model denial of service attack by sending unusual queries that are resource-intensive, continuous input overflow, repetitive long inputs, and forcing recurring resource usage through tasks in a queue.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">5. Supply chain vulnerabilities<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">There are many players involved in the world of GenAI and LLMs, including third parties who provide pre-trained models or training data, as well as LLM plugin extensions. Unlike with traditional supply chain vulnerabilities, machine learning vulnerabilities do not need to rely on software components, as developers often rely on third party downloads and packages, without considering the wider risk. Threats in this category include poisoned crowd-sourced data, vulnerable pre-trained models, a and the use of deprecated or outdated models.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">6. Sensitive information disclosure<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">In today\u2019s compliance-heavy landscape, personally identifiable information needs to be protected at all costs. However, LLMs can reveal sensitive information, including customer data, algorithms, or trade secrets and intellectual property. If a user unintentionally inputs information, it can resurface at another time. However, many users leverage LLMs without data sanitization, which stops user data becoming further training data. <\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-96885\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-3.jpg\" alt=\"biggest AppSec- related concerns Data Leakage\" width=\"676\" height=\"162\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-3.jpg 676w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/AI-Appsec-Survey-Finding-3-300x72.jpg 300w\" sizes=\"(max-width: 676px) 100vw, 676px\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Security teams should look out for incomplete filtering of sensitive information in responses, unintended disclosure of confidential information, and memorization of sensitive data in the training process.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">7. Insecure plugin design<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">For added agility, LLM plugins can be automatically called by a model, usually without the risk reduction benefit of application control. According to OWASP, they often have free-text inputs, without validation or type checking, which means an attacker could even send configuration strings instead of parameters. A threat actor can use this vulnerability to create a malicious request, forcing their agenda through the model directly, including privilege escalation, data exfiltration, and even remote code execution. Tracking authorization across plugins is critical, as you cannot simply assume that the inputs were sent by the end user.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">8. Excessive agency<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">LLMs are not predictable, we all know that by now. When LLMs present an unexpected or ambiguous output, the controls may not be in place to restrict what happens next. This is usually across three categories, the functionality of the LLM, the permissions it has, or the autonomy it holds. Either way, the developer has provided it with too much agency. Examples of each include:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Excessive functionality:<\/b><span style=\"font-weight: 400;\"> An LLM with access to plugins that can modify or delete documents, or plugins that should have been removed during testing.<\/span>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Excessive permissions:<\/b><span style=\"font-weight: 400;\"> An LLM plugin that has a generic identity as a privileged account so that it can provide answers from a document repository.\u00a0<\/span>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Excessive autonomy: <\/b><span style=\"font-weight: 400;\">A vulnerability where LLMs do not verify actions before completing them, such as deleting documents without checking with the user.<\/span><span style=\"font-weight: 400;\"><br><\/span>\n<\/li>\n<\/ul>\n<h3><span style=\"font-weight: 400;\">9. Overreliance<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Especially when leveraging a trusted source or one which has performed well for users in the past, users often take the output of an LLM as gospel. This can cause an overreliance, which becomes an issue if an LLM is hallucinating, or if the tool has been manipulated with. LLM-generated source code without oversight or validation can introduce vulnerabilities into any environment, risking the operational safety and security of an application. OWASP suggests continuous validation mechanisms for all content taken from an LLM.\u00a0<\/span><\/p>\n<h3><span style=\"font-weight: 400;\">10. Model theft<\/span><\/h3>\n<p><span style=\"font-weight: 400;\">Even a trustworthy LLM model can be accessed and manipulated by threat actors, leading to vulnerabilities. Attackers can gain unauthorized access via network misconfiguration or application security settings, or simply by querying the model API using prompt injection and then creating a shadow model. LLM model theft is a growing concern as these models have access to a huge wealth of data, and the trust of their customers. A comprehensive security framework for LLMs needs to include access control, data encryption, and scanning and monitoring processes.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-3\"><span style=\"font-weight: 400;\">Examples of AI-based Attack Scenarios Through AI and LLMs<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Let\u2019s look at just two common attack scenarios that can help you to understand in practice how developer use of LLMs can tangibly add risk or open your business up to an attack.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The first one is connected to hallucinations. There\u2019s no doubt that LLMs do hallucinate &#8211; which is any situation where the model makes up additional information to close gaps, or where assumptions are made which are incorrect. When a developer asks for code, and the package is a hallucination, it\u2019s easy to consider this merely an annoyance; you thought a package would be helpful, and actually it doesn\u2019t even exist. However, in reality, attackers can leverage hallucinations for something a lot more sinister. When attackers see that a package suggestion is a hallucination, they can then create that exact suggestion, so that when the next person is given the same hallucination in response to a similar prompt, the user will pull it down, unwittingly opening the organization to an attack.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our second example is an LLM arbitrary code exploit, which is similar to a supply chain attack. On a platform such as <\/span><a href=\"https:\/\/huggingface.co\/\"><span style=\"font-weight: 400;\">Hugging Face,<\/span><\/a><span style=\"font-weight: 400;\"> where the machine learning community can collaborate on AI and Machine Learning, there are many LLMs for developers to pull down and use. However, without robust scanning and governance, an attacker could add a malicious packet to a model, and then simply reupload it with a slightly different name. The idea is that users will download and run it, without realizing that they are injecting infected code.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-4\">\n<span style=\"font-weight: 400;\">Implementing the Right Strategies in the Era of <\/span><span style=\"font-weight: 400;\">AI Application Security<\/span>\n<\/h2>\n<p><span style=\"font-weight: 400;\">Understanding these risks doesn\u2019t mean hitting the brakes on using GenAI or benefiting from LLMs for developers. Instead, it means that organizations need to focus on implementing the right safeguards and tools to securely leverage AI in their environment &#8211; and empower developers to benefit from the latest innovation, without negatively impacting risk reduction.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">No matter what, each AI solution will have a level of risk. To reduce that risk, organizations need to go through three discrete stages:<\/span><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Assess the situation:<\/b><span style=\"font-weight: 400;\"> There is no one-size-fits-all solution for AI. Every early adopter of a new LLM or a new AI-based tool needs to consider what the risk might be. Ask yourself questions such as, is the LLM connected to public data? What community is it available to? When you know what you\u2019re dealing with, you can create guidelines accordingly.\u00a0<\/span>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Define your needs: <\/b><span style=\"font-weight: 400;\">Now that you understand the risk, have you got visibility and control? What policies do you want to put in place for usage and governance? You may need to onboard new technologies specifically for AI security and AI security testing. You will almost certainly have to implement education for developers, security teams, and the wider organization.. One example could be introducing them to tools such as <\/span><span style=\"font-weight: 400;\">modelscan.ai<\/span><span style=\"font-weight: 400;\">, which can help developers to make safer choices when leveraging LLMs.\u00a0<\/span>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Execute your solution: <\/b><span style=\"font-weight: 400;\">Now that you know the risk, and you know your preferred mitigation, it\u2019s time to execute. This could be anything from implementing any new processes and tools to launching new education programs. Make sure you can detect threats and protect your environment, and include governance and reporting that can be scaled to meet growing usage of AI, and iterated moving forward.\u00a0<\/span>\n<\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Remember, it\u2019s not about dropping the DevSecOps processes you already have in place. AI isn\u2019t coming to replace your existing processes. Instead, think about how you can leverage AI to enforce the policies and the processes you already have and that work for your teams to meet a fast-changing tech landscape and leverage new tools like LLMs to work for you. With a strong strategy around AI, you can expand the scope of what you do, while building solutions that enable smart use of the latest innovation.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Let\u2019s look at a few areas where Checkmarx have innovated with AI to accelerate AppSec teams, reduce AI-based attacks, and enable the developer workflow.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-5\">\n<span style=\"font-weight: 400;\">The Application of AI in SAST Software<\/span><span style=\"font-weight: 400;\"> from Checkmarx<\/span>\n<\/h2>\n<p><span style=\"font-weight: 400;\">At Checkmarx, we\u2019ve been thinking about protecting applications from AI risks, and using AI more widely across our platform for some time. In particular, <\/span><span style=\"font-weight: 400;\">the application of AI in SAST (Static Application Security Testing)<\/span><span style=\"font-weight: 400;\"> is one area we have built solutions for &#8211; empowering teams to use GenAI to enhance SAST and support developers in using AI and LLMs in a secure way.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AI Security Champion with auto-remediation is a great example. Of course applications will have vulnerabilities, but the real test is whether you can get them mitigated quickly and before your release date. In <\/span><a href=\"https:\/\/info.checkmarx.com\/future-of-application-security-2024\"><span style=\"font-weight: 400;\">Checkmarx\u2019 Future of Application Security Report,<\/span><\/a><span style=\"font-weight: 400;\"> we found that 29% of AppSec managers knowingly release vulnerable applications to meet a deadline.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To support teams in both identifying and solving all vulnerabilities in a significantly reduced amount of time, AI Security Champion now finds issues in the application, and provides the specific code that can then be used in the development workflow to fix the vulnerability. Developers can review the issue, and implement the fix, without any bottlenecks or further support. Without being security experts, this enables them to fix vulnerabilities at speed and scale. As Checkmarx One is fully integrated into the development workflow, the whole process takes place directly within the IDE. The developer will be presented with a Confidence Score between zero and 100 which indicates how exploitable the vulnerability is in context, an explanation of the vulnerability generated by OpenAI, the customized code snippet to remediate the issue, and the ability to ask additional questions where necessary.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Development velocity is one of the key issues that stands between security and development teams, and so this feature is a powerful tool for collaboration, too &#8211; to ensure security isn\u2019t ever put on the back burner, while enabling developers to keep to even their most ambitious timelines.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another powerful SAST tool that leverages AI is our <\/span><a href=\"https:\/\/checkmarx.com\/blog\/introducing-ai-query-builder-for-sast\/\"><span style=\"font-weight: 400;\">AI Query Builder<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><a href=\"https:\/\/checkmarx.com\/blog\/presets-queries-onboarding-the-checkmarx-one-difference\/\"><span style=\"font-weight: 400;\">Queries <\/span><\/a><span style=\"font-weight: 400;\">support AppSec teams in avoiding false positives and false negatives, and prioritizing the most critical issues within your environment.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">At Checkmarx, we use pre-built queries, as well as presets &#8211; a collection of queries which are optimized for a specific type of application, in order to define SAST scans ahead of time. Queries are written in CxSQL, our own language, and identify the most common security issues, to support customers in securing their applications as soon as they start working with Checkmarx. You can also customize them to suit your specific needs. Queries can help search for issues such as SQL injection, insecure access controls, and cross-site scripting, to name just a few.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Our AI Query Builder for SAST takes this approach to the next level, letting AI help write custom queries, or modify existing ones to help AppSec teams write new or edit existing queries. Using AI Query Builder, organizations can fine tune their queries to increase accuracy and minimize the impact of false positives or negatives. Instead of manually creating queries, managers and developers (even those without a high level of technical knowledge) can use AI Query Builder to generate tailored queries that improve risk reduction processes, and cover a far broader range of vulnerabilities across the organization.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-6\"><span style=\"font-weight: 400;\">Using AI for IaC Guided Remediation<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Instead of being handed an increasing number of problems to fix, we\u2019ve found that guided remediation empowers developers to be 60-80% closer to solving an issue. That\u2019s why we champion our AI Guided Remediation for IaC security and KICS.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Powered by GPT4, our guided remediation solution for Infrastructure as Code (IaC) guides teams through the process of fixing IaC misconfigurations, whether they have been identified through Checkmarx, or via KICS (Keeping Infrastructure as Code Secure), a free open-source solution that performs static analysis on IaC files. Just like with auto-remediation for SAST, everything takes place within the IDE, making it simpler for developers to implement fixes, and work with their day-to-day tools and processes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Whenever a vulnerability is uncovered, developers can either select from common questions or use the free-text option to ask their own questions. Without the need for pre-existing knowledge, developers can use the AI to follow actionable steps to remediate the issue, in real-time. They can then rescan, to validate that the risk has been removed. Altogether, issues in their IaC templates are resolved faster, management no longer needs to get involved with every vulnerability, and developers can feel empowered to deliver secure applications at speed.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Of course, in line with OWASP best practices, at Checkmarx, we integrate secrets detection and removal into the guided remediation process, so that sensitive information like passwords and encryption keys cannot be inadvertently shared at a later date.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-7\"><span style=\"font-weight: 400;\">AI-Driven Software Composition Analysis<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Traditionally, <\/span><a href=\"https:\/\/checkmarx.com\/learn\/software-composition-analysis\/software-composition-analysis-sca\/\"><span style=\"font-weight: 400;\">software composition analysis (SCA)<\/span><\/a><span style=\"font-weight: 400;\"> is a technology that protects organizations from the risks inherent in open-source software. While open-source components aid development velocity, they can also introduce security vulnerabilities. SCA identifies all third-party components used by an application, transitively scans dependencies, assesses all components for known risks, and recommends remediation actions. SCA also evaluates relevant third-party software license requirements and restrictions, to avoid potential compliance issues or other legal complications.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When it comes to AI, a significant part of the risk in trusting LLMs, such as ChatGPT and Copilot, is very similar to the issues described above. Our AI Security offering acts similarly with AI-generated code to how SCA operates with open source components. Checkmarx GPT provides real-time scanning of code generated by Github Copilot within the IDE, to validate the safety of the generated code, line by line, and to provide additional insight. For example, is the code a hallucination? Do\u00a0 AI-suggested open-source packages include any known vulnerabilities or malicious code? This tool is seamlessly integrated into Visual Studio, so that developers can detect and highlight potential vulnerabilities as the code is generated, providing them the power they need, directly in their workflow.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If and when a package is found to be unsafe, Checkmarx GPT\u2019s real-time scanning capability immediately provides this information to the developer. If there is not a lot of information available about a particular package, the tool educates the team about hallucinations and other risks, and may suggest alternatives to the potentially malicious package.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Going further, Checkmarx GPT does more than just scan generic code; the tool can suggest specific package versions that present the least risk, and share all the open-source licenses associated with packages, features ChatGPT and other large language models generally do not provide. Altogether, your developers and your managers will be confident that the code being pulled in is accurate, safe, the best version for the job, and without unknown license risks.\u00a0<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-8\">FAQ<\/h2>\n<h3><b>How can organizations implement AI in their security infrastructure?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">AI can enhance an organization\u2019s security infrastructure by helping to identify, assess, and remediate security risks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, AI Security Champion with auto-remediation, a capability in Checkmarx\u2019s SAST solution, can identify the code that triggers a security vulnerability. In this way, the feature helps developers hone in on the code they need to fix to remediate the issue. Similarly, the Checkmarx AI Query Builder can help AppSec teams generate queries that analyze security data.<\/span><\/p>\n<h3><b>What are the challenges of using AI in security?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">The main challenge of using AI in security is hallucination risks, which occur when an AI model generates false information. For instance, an AI-powered application security scanning tool might misidentify code as being risky when in fact it poses no security challenge. Or, a tool could hallucinate the name or version of a package when recommending how to remediate a security issue associated with an application component or dependency.<\/span><\/p>\n<h3><b>What is the role of machine learning in AI application security?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">Machine learning can enhance application security by recognizing patterns at a level of scale and complexity that traditional security techniques cannot support efficiently.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For example, an AI tool may be able to correlate data from a wide range of sources \u2013 application logs and metrics, server logs, network traffic, and so on \u2013 to assess automatically whether a given security alert is a false positive. Traditionally, teams would have performed this assessment using a mostly manual approach, which would take longer.<\/span><\/p>\n<h3><b>How does AI help in threat intelligence?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">AI can help teams leverage threat intelligence (meaning insights about potential attacks an organization may face) by helping to analyze the information and extract actionable insights quickly. This is important because threat intelligence often includes data about a wide range of potential threats, some of which pose more of a risk to an organization than others. Using AI, security analysts can focus on threats that are most likely to affect them based on considerations like which software they are running, how their software environments are configured, and which security controls they do or don\u2019t have in place to\u00a0<\/span><span style=\"font-weight: 400;\">mitigate risks.<\/span><\/p>\n<h3><b>Are there ethical considerations when using AI in security?<\/b><\/h3>\n<p><span style=\"font-weight: 400;\">While ethical considerations surrounding AI are somewhat subjective, one potential challenge is deciding whether it is acceptable to outsource important security responsibilities to AI alone. Traditionally, security analysts ultimately had to \u201cown\u201d any decisions they made regarding which risks they identified and how they reacted. But as AI-enhanced security tools become capable of performing complex tasks independently, organizations must decide whether or not they want to entrust important security-related decisions to AI alone \u2013 or whether they wish to keep a human \u201cin the loop\u201d by asking staff to verify any insights or recommendations generated by AI.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">AI in security may also create ethical challenges related to bias. These may arise if the data used to train AI-powered security tools reflects the interests of some people more than others. For instance, a tool that uses AI to assess risks may treat threats that affect users based in one country as more serious than those that affect other regions \u2013 potentially causing the security team to prioritize some users over others based on where they live.<\/span><\/p>\n<h2 class=\"article-anchor\" id=\"article-anchor-9\">\n<span style=\"font-weight: 400;\">Checkmarx\u2019 <\/span><span style=\"font-weight: 400;\">Application of AI in Security<\/span>\n<\/h2>\n<p><span style=\"font-weight: 400;\">At Checkmarx, we understand <\/span><a href=\"https:\/\/checkmarx.com\/product\/checkmarx-one-assist\/\"><span style=\"font-weight: 400;\">the potential of AI,<\/span><\/a><span style=\"font-weight: 400;\"> specifically with GenAI and LLMs, and we don\u2019t think the risks should slow your development teams down. We want to empower customers to benefit from the development velocity and knowledge sharing opportunities that come with LLMs, by offering the peace of mind that any output is going to be safe and vetted by a trusted resource, or where it\u2019s dangerous &#8211; you know that your teams will be informed about that ahead of time, too.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To make this happen, our approach to the<\/span><span style=\"font-weight: 400;\"> application of AI in cyber security<\/span><span style=\"font-weight: 400;\"> is built around two pillars:\u00a0<\/span><\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Accelerate AppSec with GenAI:<\/b><span style=\"font-weight: 400;\"> AI has huge potential for supporting AppSec teams in getting products and features to market faster, and with less risk. With IaC guided remediation for developers, and AI Security Champion with auto-remediation for SAST, our AI-based tools ensure developers are closer than ever to fixing problems, with articulate and robust results instead of a sea of challenges and false positives. While generic AI tools won\u2019t always give you the insight and intelligence you need, Checkmarx GPT helps to identify licenses, components and even alternative packages, and acts as full software composition analysis where it\u2019s needed most. <\/span>\n<\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<b>Prevention and Protection: <\/b>At the same time, the industry can\u2019t afford to ignore the threat landscape that\u2019s growing as a direct result of LLMs and GenAI. Prompt injection, AI hallucinations and AI secrets leakage all have their own unique risks attached. Checkmarx GPT and real-time scanning for GitHub Copilot in the IDE scans your LLM-generated code for vulnerabilities, while features such as AI query builder lets you get granular about the specific protections and scans you need at the earliest possible stages of the SLDC. In addition, to avoid the risk of leaking sensitive information via prompt injection, our <a href=\"https:\/\/checkmarx.com\/press-releases\/checkmarx-forges-secure-path-to-accelerate-ai-adoption-in-application-security-and-developer-workflows\/\">partnership with Prompt Security<\/a> provides browser and IDE extensions that detect the difference between secrets and code when information is shared to a GenAI or collaboration platform. Prompt Security obfuscates secrets such as credentials or IP, while sharing only the code that Checkmarx has confirmed to be non-proprietary.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\">Our own CEO, Sandeep Johri, describes the opportunity best, <\/span><i><span style=\"font-weight: 400;\">\u201cNothing more perfectly represents the decision-making tension faced by CISOs than the existence of both significant opportunities and new vulnerabilities presented by open-source and GenAI-generated code. Checkmarx has long been a pioneer in application security for enterprise customers and, with GenAI playing an increasing role in application development, we\u2019re pleased to provide the first solution to help protect against the new generation of attacks already emerging.\u201d<\/span><\/i><\/p>\n<blockquote>\n<p><span class=\"TextRun MacChromeBold SCXW240306197 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun CommentStart SCXW240306197 BCX0\">15%\u00a0<\/span><\/span><span class=\"TextRun SCXW240306197 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW240306197 BCX0\">of companies\u00a0<\/span><span class=\"NormalTextRun SCXW240306197 BCX0\">have\u00a0<\/span><span class=\"NormalTextRun SCXW240306197 BCX0\">banned AI code generation, but\u00a0<\/span><\/span><span class=\"TextRun MacChromeBold SCXW240306197 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW240306197 BCX0\">99%<\/span><\/span><span class=\"TextRun SCXW240306197 BCX0\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW240306197 BCX0\">\u00a0of security professionals\u00a0<\/span><span class=\"NormalTextRun SCXW240306197 BCX0\">see it in use, we surveyed over 900 AppSec Managers and CISOs to understand the benefits and challenges surrounding AI<\/span><\/span><\/p>\n<\/blockquote>\n<p>Download the exclusive Checkmarx-commissioned\u00a0 report <a href=\"https:\/\/checkmarx.com\/7-steps-genai-survey-gen\/\">&#8220;7 Steps to Safely Use Generative AI in Application Security<\/a>&#8221; now.<\/p>\n<p><i><span style=\"font-weight: 400;\">Looking to accelerate the use of AI in Application Security, while simultaneously securing GenAI-related threats in an increasingly complex developer environment? <\/span><\/i><a href=\"https:\/\/checkmarx.com\/request-a-demo\/\"><i><span style=\"font-weight: 400;\">Schedule a demo of our AI-based application security tools<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">.\u00a0<\/span><\/i><\/p>\n\n<section class=\"section-block-info light-theme\">\n    <div class=\"main-wrapper block-info__wrapper\">\n        <div class=\"block-info center\">\n\t\t\t\n\t\t\t<h2 class=\"section-title article-anchor\" id=\"article-anchor-10\">Integrate and automate application security in every state of your SDLC \u2013 from code to cloud.<\/h2>\t\t\t<p class=\"section-description\">DevSecOps solutions integrate, automate, and operationalize security tools and capabilities with your unique application development process.\u00a0<\/p>\n\t\t\t<div class=\"actions\">\n\t\t\t\t        <a href=\"https:\/\/checkmarx.com\/solutions\/devsecops\/\" class=\"btn btn-2 btn-bg white demo\">Discover DevSecOps<\/a>\n        \t\t\t\t        <a href=\"https:\/\/info.checkmarx.com\/devex-onboarding-best-practices?__hstc=144372074.235f1d35e33efd0ae7e293a56ce072fa.1716210555364.1727702566420.1727760814760.208&#038;__hssc=144372074.2.1727760814760&#038;__hsfp=2599978687\" class=\"btn btn-2 btn-bg border-2 demo\">Best Practices: Proven Appsec Solution Onborading<\/a>\n        \t\t\t<\/div>\n        <\/div>\n    <\/div>\n<\/section>","protected":false},"author":92,"featured_media":96910,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"learn-cat":[1276],"class_list":["post-96882","learn","type-learn","status-publish","has-post-thumbnail","hentry","learn-cat-ai-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AI in Security: Testing Guide for Application Security | Checkmarx<\/title>\n<meta name=\"description\" content=\"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AI in Security: Testing Guide for Application Security | Checkmarx\" \/>\n<meta property=\"og:description\" content=\"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-15T20:35:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1792\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"23 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\"},\"author\":{\"name\":\"Jonathan Singer\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19\"},\"headline\":\"AI Security Testing: Safeguarding DevSecOps in the Age of GenAI and LLMs\",\"datePublished\":\"2024-07-31T13:04:45+00:00\",\"dateModified\":\"2026-04-15T20:35:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\"},\"wordCount\":4607,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\",\"url\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\",\"name\":\"AI in Security: Testing Guide for Application Security | Checkmarx\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg\",\"datePublished\":\"2024-07-31T13:04:45+00:00\",\"dateModified\":\"2026-04-15T20:35:08+00:00\",\"description\":\"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg\",\"width\":1792,\"height\":1024,\"caption\":\"Application of AI in Application Security: Testing Guide and Resource\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19\",\"name\":\"Jonathan Singer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg\",\"caption\":\"Jonathan Singer\"},\"url\":\"https:\/\/checkmarx.com\/author\/jonathansinger\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AI in Security: Testing Guide for Application Security | Checkmarx","description":"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/","og_locale":"en_US","og_type":"article","og_title":"AI in Security: Testing Guide for Application Security | Checkmarx","og_description":"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.","og_url":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2026-04-15T20:35:08+00:00","og_image":[{"width":1792,"height":1024,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"23 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/"},"author":{"name":"Jonathan Singer","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19"},"headline":"AI Security Testing: Safeguarding DevSecOps in the Age of GenAI and LLMs","datePublished":"2024-07-31T13:04:45+00:00","dateModified":"2026-04-15T20:35:08+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/"},"wordCount":4607,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/","url":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/","name":"AI in Security: Testing Guide for Application Security | Checkmarx","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg","datePublished":"2024-07-31T13:04:45+00:00","dateModified":"2026-04-15T20:35:08+00:00","description":"Explore how GenAI and LLMs are transforming application development and security. Learn key AI security testing strategies to help DevSecOps teams mitigate risks and build secure, AI-driven applications.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/learn\/appsec\/the-complete-guide-to-ai-application-security-testing\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/07\/The-Complete-Guide-to-AI-Application-Security-Testing.jpg","width":1792,"height":1024,"caption":"Application of AI in Application Security: Testing Guide and Resource"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19","name":"Jonathan Singer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg","caption":"Jonathan Singer"},"url":"https:\/\/checkmarx.com\/author\/jonathansinger\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn\/96882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/learn"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/92"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn\/96882\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/96910"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=96882"}],"wp:term":[{"taxonomy":"learn-cat","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/learn-cat?post=96882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}