AI Pen Testing Killed Traditional DAST episode artwork

EPISODE · Aug 31, 2026 · 43 MIN

AI Pen Testing Killed Traditional DAST

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on every pull request is realistic, and what stops an autonomous tester from going further than it should. Then we look further out: the future of bug bounties, what happens when cloud and model providers absorb today's security tooling, and who is accountable when an agent deletes your production database.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with James Berthoty:→ James Berthoty on LinkedIn→ Latio→ Latio PulseMentioned in this episode:→ Latio's free reports→ James on the podcast the first time: Is DAST Dead? And the future of API securityFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the results speak for themselves01:01 Meet James Berthoty and the "Is DAST dead?" fallout01:31 Chickens, eggs, and getting away from screens03:46 Why we're revisiting the DAST question04:14 A working definition of AI pentesting05:47 Contextual payloads and application awareness06:47 Determinism, repeatability, and what buyers actually want07:46 Can you run an AI pentest on every code change?09:43 What it really costs10:40 Incumbents vs. AI-native vendors13:27 Who pays for the tokens?14:29 Bundling, platforms, and competitive pressure16:25 AI across the whole development workflow18:22 Agents that run all the way to deployment19:21 A pentest on every pull request21:52 What stops a pentest from going too far?23:10 Permission scoping and guardrails26:07 Where the findings actually land28:02 The future of bug bounties30:50 Why pentests command more budget than DAST31:45 Could the cloud providers absorb security tooling?34:38 What model providers could build instead36:36 The same story on the code scanning side39:24 Accountability when the tool misses something40:22 Shared responsibility when an agent deletes production41:23 The verdict on DAST42:19 Where to find Latio's free reports43:15 Closing thoughts

Episode metadata supplied by the publisher feed · Published Aug 31, 2026

Embed this episode

Is traditional DAST finally dead? James Berthoty came back to settle the argument that his last episode started. James is the founder and analyst behind Latio, and he argues that AI pentesting is a genuinely different animal — payloads generated with context about your actual application, agents that chase findings the way a human tester would, and results a scanner was never going to produce. We get into what it costs once tokens enter the picture, who pays for them, whether a pentest on eve...

Distinct summary based on available episode metadata or transcript content.

Ready to play

AI Pen Testing Killed Traditional DAST

0:00 43:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 43 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 31, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!