Uploaded December 2025 | Updated September 2026, 1 week ago
Large Language Models (LLMs) are making their way into application security (AppSec), promising to speed up vulnerability detection, code reviews, and even pentesting. Sounds great, right? The problem is, LLMs are confident, creative, and still unreliable when left unsupervised.
Security teams are eager to use AI for threat modeling, secure code generation, and policy enforcement, but these models still hallucinate vulnerabilities, suggest insecure fixes, and miss subtle security risks that a human would catch. Instead of solving security, AI is just shifting the problem in new (and sometimes unpredictable) ways.
This talk dives into real-world failures where AI-assisted security tools missed threats or created new ones, why human oversight is still crucial, and how future AI models might finally reduce the babysitting burden.
Vineeta Sangaraju
Senior Research Engineer
Vineeta is a seasoned security researcher. She focuses on crafting innovative solutions that enhance application security. Her research further influences static analysis solutions across the server-side, mobile and client-side domains. Armed with a master's degree in Computer Science from Indiana University, she has over 7 years of experience in the field. She also enjoys sharing her knowledge at application security conferences as a presenter. Vineeta's ideal day involves laying in the grass on a sunny day reading a fantasy or sci-fi book.
linkedin.com/in/vineetasangaraju
blackduck.com/blog/authors/vineeta-sangaraju.html (blog)
Managed by the OWASP® Foundation
owasp.org
Large Language Models (LLMs) are making their way into application security (AppSec), promising to speed up vulnerability detection, code reviews, and even pentesting. Sounds great, right? The problem is, LLMs are confident, creative, and still unreliable when left unsupervised.
Security teams are eager to use AI for threat modeling, secure code generation, and policy enforcement, but these models still hallucinate vulnerabilities, suggest insecure fixes, and miss subtle security risks that a human would catch. Instead of solving security, AI is just shifting the problem in new (and sometimes unpredictable) ways.
This talk dives into real-world failures where AI-assisted security tools missed threats or created new ones, why human oversight is still crucial, and how future AI models might finally reduce the babysitting burden.
Vineeta Sangaraju
Senior Research Engineer
Vineeta is a seasoned security researcher. She focuses on crafting innovative solutions that enhance application security. Her research further influences static analysis solutions across the server-side, mobile and client-side domains. Armed with a master's degree in Computer Science from Indiana University, she has over 7 years of experience in the field. She also enjoys sharing her knowledge at application security conferences as a presenter. Vineeta's ideal day involves laying in the grass on a sunny day reading a fantasy or sci-fi book.
linkedin.com/in/vineetasangaraju
blackduck.com/blog/authors/vineeta-sangaraju.html (blog)
Managed by the OWASP® Foundation
owasp.org










