WorkThe story, in brief

The Future Of AppSec May Be Autonomous, But The Present Is Surprisingly Practical

AppSec teams are adopting AI today—not for autonomy, but for triage. Vendors are betting on agents; practitioners are betting on accuracy.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI is moving from vendor hype to practical deployment in application security, but adoption is constrained by trust and ROI uncertainty rather than capability. This is an industry in transition, with practitioners skeptical of autonomous claims.

The key facts

9 to know
  1. AI adoption in AppSec constrained by trust concerns, value questions, and pricing uncertainty

  2. Vendors aggressively investing in autonomous agent capabilities

  3. Practitioners using AI for risk identification, prioritization, and remediation—not full autonomy

  4. Gap between vendor roadmap (autonomous agents) and customer reality (practical tooling)

  5. AI becoming core to AppSec tools for risk identification, prioritization, remediation

  6. Vendor investment aggressive but adoption constrained

  7. Key barriers: trust concerns, value uncertainty, pricing model confusion

  8. Gap between autonomous-agent narrative and practical near-term deployments

  9. Forrester report on AppSec AI adoption trends

Go to the source

Forrester Blogforrester.com

Publisher excerpt: AI is no longer a future feature in application security; it is rapidly becoming a core part of how application security (AppSec) tools identify, prioritize, and remediate risk. Yet despite aggressive vendor investment, adoption remains constrained by trust concerns, questions about value, and…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work