EPISODE · Aug 26, 2026 · 47 MIN
AI Security: OWASP Meets Global Standards
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Rob van der Veer:→ Rob van der Veer on LinkedIn→ OWASP AI Exchange→ MOSAICMentioned in this episode:→ OpenCRE→ Luna and the Magic AI PaintbrushFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — don't be surprised when the AI breaks out of the cage01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 50005:24 Defining responsible AI07:41 Fairness, protected attributes, and transparency09:34 The EU AI Act and what regulation actually asks of you11:27 How AI changes every part of software development13:23 Where responsibility lands15:20 You're not defending your own data center17:19 What traditional AppSec teams consistently miss about AI18:18 Finding vulnerabilities in AI-generated code19:19 Too many standards — and using AI to write them20:51 MOSAIC: eight standards bodies, one agreement22:09 One machine-readable taxonomy with OpenCRE23:06 Can AI level the field between attackers and defenders?25:59 When AI security becomes security theater26:56 What agentic red teaming actually looks like29:44 When agents exceed their scope32:43 Luna and the Magic AI Paintbrush33:40 Do we sandbox the agents?34:40 Guardrails without killing creativity36:39 Skill atrophy when AI is your only way forward40:04 "How do we hit this quarter?" and the pressure to ship43:16 Everyone is selling agentic security45:07 Key takeaways and where to start with the AI Exchange47:12 Closing thoughts
Embed this episode
What this episode covers
AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into ag...
Ready to play
AI Security: OWASP Meets Global Standards
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.