LLMs in AppSec: Why They Still Need a Chaperone @OWASPGLOBAL
LLMs in AppSec: Why They Still Need a Chaperone  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
Large Language Models (LLMs) are making their way into application security (AppSec), promising to speed up vulnerability detection, code reviews, and even pentesting. Sounds great, right? The problem is, LLMs are confident, creative, and still unreliable when left unsupervised.

Security teams are eager to use AI for threat modeling, secure code generation, and policy enforcement, but these models still hallucinate vulnerabilities, suggest insecure fixes, and miss subtle security risks that a human would catch. Instead of solving security, AI is just shifting the problem in new (and sometimes unpredictable) ways.

This talk dives into real-world failures where AI-assisted security tools missed threats or created new ones, why human oversight is still crucial, and how future AI models might finally reduce the babysitting burden.

Vineeta Sangaraju
Senior Research Engineer

Vineeta is a seasoned security researcher. She focuses on crafting innovative solutions that enhance application security. Her research further influences static analysis solutions across the server-side, mobile and client-side domains. Armed with a master's degree in Computer Science from Indiana University, she has over 7 years of experience in the field. She also enjoys sharing her knowledge at application security conferences as a presenter. Vineeta's ideal day involves laying in the grass on a sunny day reading a fantasy or sci-fi book.
linkedin.com/in/vineetasangaraju
blackduck.com/blog/authors/vineeta-sangaraju.html (blog)

Managed by the OWASP® Foundation
owasp.org
LLMs in AppSec: Why They Still Need a ChaperoneAI Goat: A Damn Vulnerable AI Infrastructure - Ofir Yakobi & Shir SadonThe History of the OWASP Developer GuideOWASP AI Exchange experts on the future of security for AI - Panel hosted by Chloé Messdaghi5 Steps to VEX Success: Managing the End-to-End Workflow - Cortez Frazier Jr.AppSec Israel HighlightSo You Want To Be An OWASP Speaker?Defending Against New Phishing Attacks that Abuse OAuth Authorization Flows - Jenko HwongSecurity Champions at Scale: Transforming Security Culture by Aligning Incentives and Gamification202010 October 2020 Global Board MeetingConnecting the dots: 5 lessons learned from an 8 year journey of an AppSec Program track 1Beyond the Checklist: Building an AppSec Culture That Engineers Don’t Dread
OWASP Foundation |

LLMs in AppSec: Why They Still Need a Chaperone

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER