Michael Burch - AI-Enabled Citizen Developers episode artwork

EPISODE · Jun 16, 2026 · 48 MIN

Michael Burch - AI-Enabled Citizen Developers

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael argues for sandboxed workflows, automated security controls, clear limits, and AI champion programs that quietly carry security practices into every team. The discussion closes on evaluating generated code, token-cost incentives, and the need to define a measurable outcome before buying licenses or opening production access.Connect with Michael Burch:→ Michael Burch on LinkedIn→ Security JourneyMentioned in this episode:→ SecureMyVibe→ Manicode Security→ The Security Champions Podcast→ OWASP Low-Code/No-Code Top 10→ Claude CodeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Michael Burch02:12 From Army Ranger to AppSec education05:40 What is an AI-era citizen developer?06:52 When low-code guardrails disappear08:49 Giving GitHub to 200 nondevelopers12:16 The rollout is already underway13:23 What happens outside the pipeline17:20 Training gaps and adoption without outcomes20:03 Measuring ROI instead of usage22:28 Why prompt libraries are not enough25:28 Sandboxing citizen developers28:36 Are organizations waiting for a breach?29:56 Turn security champions into AI champions32:00 How AppSec teams need to change34:58 Guardrails, expectations, and saying no38:41 Can developers evaluate generated code?42:40 Token pricing and platform lock-in44:36 When token usage becomes the wrong incentive46:17 A practical plan for citizen development48:28 Closing thoughts

Episode metadata supplied by the publisher feed · Published Jun 16, 2026

Embed this episode

When every employee can generate working software, who owns the risk? Michael Burch, VP of AI Enablement and Acceleration at Security Journey, explains how AI is turning nondevelopers into citizen developers faster than enterprises can build guardrails around them. He and the hosts examine rollouts that hand GitHub and Claude Code to hundreds of employees, the danger of measuring adoption instead of business value, and why prompt libraries alone do not meet people where they work. Michael arg...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Michael Burch - AI-Enabled Citizen Developers

0:00 48:58

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 48 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 16, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!