AI is building your software. Who's making the security decisions?
AI coding assistants are changing how software gets built. Traditional AppSec tools focus heavily on scanning the final code artifact, but as AI agents move from simple code dependencies to autonomous decision-makers and execution paths, traditional security controls enter the process too late.
In this session, Ashley Delonso (Senior Product Marketing Manager at Mend.io) and Gil Rigbi (General Manager at Mend AI) break down the evolution of AI supply chain risks. Discover why old payloads are entering through entirely new entry points, how to move from detection controls to decision influence, and the five practical disciplines required to secure software in an AI-native world.
Key Timestamps
00:10 – Introduction and speaker roles
01:08 – The shift in software supply chain risks
02:42 – AI supply chain threat categories
05:14 – Old payloads, new entry points
06:36 – The 3 roles of AI: Dependency, decision-maker, and execution path
08:42 – The core SDLC assumption: Human vs. AI decision-making
11:08 – Detection controls vs. decision influence
13:28 – What is slop squatting?
17:13 – Scenario: AI agents and the lack of security context
20:05 – Threat hunting & the loss of context in root cause analysis
22:20 – Models, MCP servers, and autonomous permissions
23:21 – The leadership test: Mapping AI assets and access
27:28 – The interaction layer: Bridging the code layer and the AI layer
31:08 – 5 disciplines to secure AI-driven software development
34:31 – Key takeaways: Securing AI actions and decisions
36:25 – Live Q&A and additional resources