{"id":26182,"date":"2026-09-21T15:13:55","date_gmt":"2026-09-21T23:13:55","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/why-ai-coding-makes-zero-trust-an-appsec-requirement\/"},"modified":"2026-09-21T15:13:55","modified_gmt":"2026-09-21T23:13:55","slug":"why-ai-coding-makes-zero-trust-an-appsec-requirement","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/why-ai-coding-makes-zero-trust-an-appsec-requirement\/","title":{"rendered":"Why AI coding makes zero trust an AppSec requirement"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Feeling comfortable about the safety of your software supply chain because your organization has invested in SBOMs, signing, and provenance? You shouldn\u2019t.<\/p>\n<p>In the AI coding era, those tenets of the traditional trust model aren\u2019t enough to ensure software safety. That\u2019s because that model fails to answer an important security question: What is the code capable of doing?<\/p>\n<p>CodeHunter CEO Ken Ammon, <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/13\/sbom-zero-trust-for-code\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">writing for Help Net Security<\/span><\/a>, summarized the trust vacuum.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201c[T]raditional trust models are insufficient when AI generates, modifies and deploys code faster than human review can keep up. We can no longer trust software based primarily on what it is, where it came from or whether it resembles something seen before.\u201d<\/em><br \/><em>\u2014<\/em>Ken Ammon<\/p>\n<p>Brett Smith, a software developer at SAS, said trusted sources, signatures, SBOMs, and provenance prove identity and origin, but they don\u2019t prove intent or safety.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cA binary can be signed by a trusted vendor and have a perfect provenance chain and yet still be malicious if the build pipeline was compromised or contains a zero-day vulnerability.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/brett-smith-15b3737\/\"><span style=\"text-decoration:underline\">Brett Smith<\/span><\/a><\/p>\n<p>Here\u2019s why zero trust is now essential to application security (AppSec).<\/p>\n<p><strong>[ Join webinar: <\/strong><a href=\"https:\/\/www.reversinglabs.com\/events\/independently-verified-sboms\"><strong>Independently Verified SBOMs: Why Trust Is No Longer Enough<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"its-now-trickier-to-spot-malicious-code\">It\u2019s now trickier to spot malicious code<\/h2>\n<p>SBOMs, signing, and provenance answer important questions, but AI coding brings new questions that they don\u2019t address, said Jeff Williams, CTO and co-founder of Contrast Security and founder of OWASP.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAn SBOM tells you what components are present. A signature establishes who signed an artifact and whether it was modified. Provenance tells you where it came from and how it was built. None of that tells you whether the developer made a mistake, whether a trusted contributor or build environment was compromised, or whether the software will behave dangerously in your environment.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/planetlevel\/\"><span style=\"text-decoration:underline\">Jeff Williams<\/span><\/a><\/p>\n<p>We need to recognize that dangerous code can have a perfectly documented chain of custody. \u201cThis becomes even more obvious with agentic systems,\u201d Williams said. \u201cThe same legitimate model, tools, and components can produce safe or dangerous behavior depending on the goal, context, data, and sequence of decisions made at runtime.\u201d<\/p>\n<p><template id=\"P:8\"><\/template><template id=\"P:9\"><\/template><template id=\"P:a\"><\/template><template id=\"P:b\"><\/template><template id=\"P:c\"><\/template><template id=\"P:d\"><\/template><template id=\"P:e\"><\/template><template id=\"P:f\"><\/template><template id=\"P:10\"><\/template><template id=\"P:11\"><\/template><template id=\"P:12\"><\/template><template id=\"P:13\"><\/template><template id=\"P:14\"><\/template><template id=\"P:15\"><\/template><template id=\"P:16\"><\/template><template id=\"P:17\"><\/template><template id=\"P:18\"><\/template><template id=\"P:19\"><\/template><template id=\"P:1a\"><\/template><template id=\"P:1b\"><\/template><template id=\"P:1c\"><\/template><template id=\"P:1d\"><\/template><template id=\"P:1e\"><\/template><template id=\"P:1f\"><\/template><template id=\"P:20\"><\/template><template id=\"P:21\"><\/template><template id=\"P:22\"><\/template><template id=\"P:23\"><\/template><template id=\"P:24\"><\/template><template id=\"P:25\"><\/template><template id=\"P:26\"><\/template><template id=\"P:27\"><\/template><template id=\"P:28\"><\/template><template id=\"P:29\"><\/template><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Feeling comfortable about the safety of your software supply chain because your organization has invested in SBOMs, signing, and provenance? You shouldn\u2019t.In the AI coding era, those tenets of the traditional trust model aren\u2019t enough to ensure software safety. That\u2019s because that model fails to answer an important security question: What is the code capable of doing?CodeHunter CEO Ken Ammon,writing for Help Net Security, summarized the trust vacuum.\u201c[T]raditional trust models are insufficient w<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26182","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26182"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26182\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26182"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}