EPISODE · Sep 15, 2026 · 36 MIN
How Agentic AI Fails—and Which Controls Actually Stop It
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer refund" AI agent scenario step by step, showing how AND/OR gates and minimal cut sets turn vague worry into ranked, data backed probabilities. They dig into where AI helps build a tree, and where garbage in, garbage out still applies, why "comprehensive test coverage" is a myth, and how attaching real dollar figures to failure paths makes it easier to sell security controls to leadership.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Petra Vukmirovic:→ Petra Vukmirovic on LinkedIn→ OWASP Threat Model LibraryMentioned in this episode:→ Adam Shostack: "Stop Trying to 'Manage Risk'" (keynote)→ OWASP Global AppSec USA 2026 (San Francisco, Nov 5–6)Follow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the math behind where to put your controls01:09 Meet Petra Vukmirovic01:28 Petra's origin story: from ER doctor to AppSec02:50 Career path: engineer to Head of InfoSec at Numan04:18 What is fault tree analysis, and where threat modeling ends06:22 Can AI actually do fault tree analysis?08:12 Walking the "wrong customer refund" agent example12:33 Storing your trees: JSON vs. Markdown16:08 Why conjunctive failures trip up narrow thinking17:27 Top 3 failure modes when agents touch downstream systems19:29 Real story: an agent pushed code to main without approval21:27 Testing: why "comprehensive coverage" is a myth23:54 How rough is rough? Assigning probabilities28:08 Getting started without a six week science project31:35 Using FTA to sell controls and build credibility33:43 The epiphany: FTA is about controls, not faults34:48 The one thing every agentic team should add today35:48 Closing thoughts and OWASP Global AppSec USA preview
Embed this episode
What this episode covers
Most fault trees get built on gut feeling. Petra Vukmirovic did something rarer: she borrowed the actual math from aviation and nuclear-plant safety engineering and pointed it at AI agents. Petra traded emergency medicine for application security and now heads information security at Numan — and she joins Chris Romeo and Robert Hurlbut to make the case for fault tree analysis (FTA), the deductive method that picks up exactly where threat modeling stops. Petra walks through a "wrong customer r...
Ready to play
How Agentic AI Fails—and Which Controls Actually Stop It
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.