AI has accelerated software development and, along with it, an exponential increase in vulnerability backlog.
In a conversation with Sandeep Johri, CEO, Checkmarx, we uncover insights into how AI is reshaping application security (AppSec) as software development accelerates and the window for attackers to exploit vulnerabilities shrinks.
He believes organizations need to rethink traditional approaches to detection, prioritization and remediation.
We also find out how – in the face of AI-driven vulnerability debt – frontier AI models and agentic capabilities can help enterprises scale AppSec while maintaining accuracy, governance, data privacy and human oversight.

Sandeep Johri, CEO, Checkmarx
AI is accelerating software development, but it is also accelerating the discovery and exploitation of vulnerabilities. How is that changing the risk equation for organizations today? Is this an inflection point for application security?
Sandeep: With the rapid adoption of AI tools, the volume of code that is being generated has gone up significantly. Most companies are expecting 2x the amount of code in the next 18 months from where they are because of agentic coding assistance.
On the one hand, the challenge is that auto-generated code has 2 to 3x the vulnerability density of human-generated code. So, while your code base is increasing, your vulnerability debt is increasing even faster. That’s the trade-off.
If this vulnerability debt isn’t addressed early enough, you will not be able to ship the product or deliver the code.
In the face of such a vulnerability debt, with AI shrinking the window between vulnerability introduction and exploitation, does the traditional AppSec playbook still work?
Sandeep: It has to change significantly because the vulnerability backlog is accelerating.
AppSec way back used to be a post-build function, and over the last decade, it has been moving to a DevSecOps function, where it’s fully integrated into the development lifecycle. However, it was still mostly a manual process.
In an agentic AI-assisted world, you really have to prevent as much of the vulnerability as possible in the AI generated code… you’ve got to catch it early, shift left as fast as possible.
You triage them and remediate as fast as you’re generating code. You have to remediate at machine speed, otherwise you will slow it all down.
There’s a proliferation of ‘AI-powered’ security tools out ther. How is Checkmarx, especially Fusion, different?
Sandeep: Fusion is AI-powered, but the power that we combine both deterministic and probabilistic engines… and our engines are the best in the industry: we have the highest fidelity of results in our deterministic engine.
If you rely only on probabilistic engines, which mean LLMs, you do not get a comprehensive perspective, because while LLMs discover some new things, they also miss a lot of known vulnerabilities.
For example, cloud code security is nothing but a security harness around an LLM.
In Fusion’s blended model, we take results from a deterministic engine and from a probabilistic engine, and it’s like a Venn diagram. There are some duplicates. There are some things that deterministic finds that LLMs don’t, and there are some things that LLM finds that deterministic don’t.
There are also a lot of false positives because LLMs tend to be very noisy, so we then suppress the false positives so that we can identify the highest-fidelity results. We get four to five times the vulnerabilities identified when we combine the two, compared to a cloud code security model.
You’ve also introduced Checkmarx Triage & Remediation Assist, with agents that can assess whether findings are actually exploitable and then generate a merge-ready fix. Can AI actually help distinguish which vulnerabilities really matter?
Sandeep: We have developed an agent that uses all our security knowledge and leverages LLMs to triage vulnerabilities because we are finding a lot more vulnerabilities than before.
We triage them based on reachability, attackability, and the context of the enterprise and the context of the application, to be able to prioritize because right now you have more vulnerabilities than you can resolve.
With all this talk about autonomous agents, do you see them replacing developers or AppSec engineers?
Sandeep: You’re actually, going to need more developers, not fewer because you’re generating more code, and it needs to be analyzed.
I liken it to when PCs came – they didn’t eliminate people. They actually made people more productive. So people are expected to do more, and this is now the same situation with developers and in AppSec.
I don’t know of any company that has cut their engineers by half. What I’m seeing is that the younger engineers are better at adopting AI tools than the older ones. We are actually seeing some of the youngest engineers producing the most by leveraging AI tools.
What does effective human oversight look like in an AI-heavy development environment?
Sandeep: Almost all our customers have adopted coding assistance. So, at the source, at the code generation level, developers are using coding assistance to significantly improve the productivity of code generation. They have agents that do code review, but you still need a human involved in that.
We have a remediation agent that can develop the remediation, but almost every customer wants a human in the loop to review before they put it in, because LLMs are not perfect. They can hallucinate. They can check and countercheck, but you still want some human checks.
And just like human employees, they need guardrails. They need guidance. They need mentorship. They need controls. They need security controls. You need to have a learning agent that is observing, seeing what is done right, and fixes what goes wrong.
Agents in that sense will be like human workers. It’s not like you hire somebody and magically everything gets solved.
Finally, what does enterprise-grade AI security look like for the organisation of tomorrow?
Sandeep: AI is changing security in every way – in every area, in the development environment, in the code base.
There’s agentic code development, and therefore you have to have agentic code security checking and discovery, and then agentic remediation to really be able to keep up to speed.
The velocity of threats and the time to threat has increased significantly, and the sophistication of the threats has also increased dramatically. So you need agentic analysis for threat and incident events. You can no longer just have humans analyze that.
Security stacks must be modernized. You need modern tooling that can handle the AI velocity of attacks. But then you also have to have governance on top so that you can make sure that you’re doing the right thing and doing it sufficiently well.
AI raises the stakes on all of that. When code and threats both move at machine speed, you can’t fall back on manual checks. It comes down to three things: a comprehensive view of what’s actually exploitable, a process to prioritize and fix it, and proof that it got fixed. That discipline has to hold across every team and every tool. That’s what enterprise-grade AI security looks like, and that’s what Checkmarx is built to deliver.
