For technology leaders, the management question is no longer whether AppSec tools can find defects, but who is accountable for stopping risky code before it reaches production. Agentic development changes the operating model: security canโt remain a late-stage review function if AI tools are generating code, dependencies and infrastructure decisions at machine speed. That pushes AppSec toward continuous, policy-driven controls with clearer decision rights between engineering, platform teams, product owners and security.
The strategic trade-off is between breadth of coverage and depth of actionability. Many organisations already own overlapping scanners, but the higher-value capability is correlation: exploitability, runtime exposure, reachability and business impact. Leaders should expect to rationalise tools around that outcome, not around feature counts. The next portfolio question is whether current spend is funding more alerts or better intervention.
That creates governance implications. If autonomous agents can introduce insecure patterns, then controls need to be embedded in the development workflow, not delegated to periodic review boards. Management should define which policy failures block builds, which trigger human approval, and which are auto-remediated. This is also a vendor-management issue: buyers will need evidence that tools can validate fixes, integrate with developer workflows, and support auditability across code, dependencies, and runtime signals.
Next questions for CIOs and AppSec leaders: Which risks are we willing to allow AI agents to decide? Where do we need mandatory guardrails versus advisory controls? How will we measure success: fewer findings, fewer exploitable issues, faster remediation, or lower production risk? The answer will determine whether AppSec remains a scanning function or becomes a core part of the software delivery operating model.
Application security testing (AST) has reached an inflection point. The market is crowded, capabilities overlap, and detection alone is no longer a source of durable differentiation. DevOps platforms embed security features. Cloud-native application protection platform vendors continue to push left. Application security posture management specialists offer open-source scanning technologies. And AI frontier labs such as Anthropic and OpenAI experiment with new approaches to code security. The result is a noisy ecosystem where most tools can find issues but far fewer can reliably tell teams which ones matter and how to fix them.
- Detection is becoming commoditized; context is not. Static application security testing, dynamic application security testing, software composition analysis, secrets scanning, infrastructure-as-code scanning, and container image scanning are table stakes. What separates leaders from laggards is the ability to correlate findings with real-world context: exploitability, reachability, runtime exposure, and business impact. Buyers increasingly expect security tools to identify which vulnerabilities are actually exploitable in production and produce fixes that developers can trust. This shift explains why prioritization, validation, and remediation are now the battlegrounds of application security.
- LLMs are reshaping how security tools reason about risk. LLMs excel at correlating disparate data sources such as code repositories, dependency heuristics, security scanners, runtime signals, and workflows into coherent insights. Applied well, this enables fewer false positives, more actionable findings, and remediation that reflects how software is actually built and deployed. New entrants can leverage these strengths to address long-standing criticisms of legacy AST approaches but typically are not replicating their depth or breadth of coverage. The value is no longer in how much you detect but in how well you understand and act on what you detect.
- Software development itself is becoming agentic, generating insecure code at scale. AI-coding assistants, autonomous coding agents, and AI-driven workflows are moving from experimentation to daily use. These systems generate code, select dependencies, modify infrastructure, and execute instructions at machine speed. But AI coding agents commonly ship unauthenticated or improperly authorized endpoints, trust client-supplied data for security-critical decisions (e.g., prices, roles, state), and omit basic controls such as input validation, rate limiting, and server-side checks โ resulting in code that works functionally but is exploitable by default. They also frequently reuse insecure patterns (string-built queries, unsafe file handling, eval/exec) because they optimize for correctness and brevity, not risk.
Traditional application security (AppSec) models designed for human-paced development and discrete scanning stages are poorly suited to this reality. Securing agentic development requires controls that operate continuously, reason autonomously, and intervene in real time.
Introducing Agentic Development Security (ADS)
ADS is not a single product category or a rebranding of existing tools. It is a new security paradigm focused on protecting AI-powered software development from end to end. ADS spans prevention, detection, prioritization, and remediation while providing continuous intelligence across code, dependencies, workflows, and running applications. Crucially, it treats security decisions as autonomous, policy-driven actions, not just alerts handed to overburdened teams.
ADS platforms must identify and mitigate application layer risks unique to AI-driven applications. This includes detecting classes of flaws outlined in the OWASP Top 10 for LLLM Applications such as prompt injection, unsafe output handling, excessive agency, and missing controls across both development and runtime contexts. As agentic applications mature, this capability will need to extend beyond single-model interactions to analyze multiagent workflows, tool invocation chains, autonomous decision paths, and policy enforcement gaps. The goal is not just model safety but assurance that AI-powered applications behave predictably, securely, and within intended operational boundaries.
Core ADS Capabilities Cluster Around A Few Themes
Rather than isolated tools, ADS platforms combine multiple intelligence and control layers that will continue to evolve:
- AI-driven code and dependency analysis that goes beyond pattern matching to assess exploitability, logic flaws, and real risk in context.
- Guardrails for AI-assisted coding that guide agents and developers toward secure outcomes and prevent unsafe instructions from executing.
- Intelligent triage and prioritization that continuously ranks findings based on exposure and business impact.
- Automated remediation for both code and dependencies, producing validated fixes that preserve functionality.
- Dynamic testing of live applications and APIs that adapts to application behavior and modern architectures to detect OWASP Top 10 for LLM Applications flaws
- Policy-driven software development lifecycle quality gates enforced by autonomous agents rather than manual review.
- Supply chain and toolchain protection, including AI coding agents, extensions, Model Context Protocol servers, agent skills, pipelines, and artifacts.
- Governance, reporting, and risk analytics that provide durable insight over time, not just point-in-time results.
Today, No Single Vendor Delivers The Full ADS Vision
Some vendors excel at code analysis, others at supply chain analysis, and others at runtime intelligence or governance. Whatโs missing is a unified operating model that treats security as an autonomous, continuous function aligned to agentic development. This fragmentation is not surprising; the paradigm is still forming, but it creates both risk and opportunity for buyers and vendors alike.
Forrester Will Evaluate This Emerging Space
Our upcoming agentic development security landscape report and Forrester Waveโข evaluation will identify the vendors pushing the market forward, clarify how capabilities align to this new model, and help security and development leaders understand where todayโs tools fall short โ and where they lead.
As development becomes agentic, security must do the same. Incremental improvements to legacy AppSec will not be enough. If youโre evaluating how AI coding agents change your application security strategy, creating AI applications, or want to understand which vendors are shaping agentic development security, watch for Forresterโs upcoming ADS landscape and Wave and reassess whether your current AppSec model is built for an agentic future โ or schedule a meeting with me.
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

