Cycode released compelling new research from RSA Conference 2025 that exposes significant insight into
the future of application security. While 60% of professionals are still in the
early stages of adopting agentic AI, the study clearly demonstrates that those
who have embraced it are realizing substantial gains in developer and security
team productivity, directly translating to more effective and efficient
security practices that ultimately help reduce risk.
With nearly 50%
planning to embrace agentic AI in the coming year, the survey uncovers a
significant untapped market in AI-native application security. While many
readily embrace AI for productivity gains and time savings, granting AI systems
autonomous decision-making authority represents a significant leap for some
organizations in the initial stages of AI adoption. This gradual adoption rate
stems from a cautious approach, which is understandable, as organizations seek
innovative solutions to adapt to the rapid and complex demands of modern
development ecosystems.
Despite the
current adoption rates of agentic AI, awareness of its potential benefits for
application security is growing, highlighting the importance of market
education about the advantages and risks of agentic AI to overcome reluctance.
The survey
revealed that 30% of respondents believe integrating agentic AI into CI/CD
pipelines will significantly enhance the application development process. This
aligns with the idea that AI can accelerate development and streamline
workflows more efficiently, transforming application security in the era of 10X
developer output. For example, with the rise in "vibe coding,"
developers are shipping more code, faster and more frequently. While this
doesn't change the AppSec-to-developer ratio, it can create the perception that
the ratio is widening, leaving security teams struggling to keep pace. Although
45% of respondents have a 1:50 to 1:100 ratio, 26% indicated a 1:500 to 1:1000
ratio, showcasing an increase in the gap between application security and development
resources. This situation creates immense pressure on that lone defender, which
could be alleviated with the right agentic AI-powered security tools.
The survey also
found that when it comes to agentic AI:
- 44%
of survey respondents believe that agentic AI's capabilities will help
teams with identification, prioritization and remediation of
vulnerabilities.
- 38%
of cybersecurity professionals believe it can enhance application security
testing (AST), showcasing the importance of intelligent AI-human
partnerships in improving security to streamline the identification,
prioritization, and remediation processes.
- More
than half (52%) of respondents agree that when integrated with AST tools,
agentic AI's pre-commit hooks effectively maintain security checks during
code commits. This demonstrates how AI, when applied appropriately, can
help security teams manage overwhelming tasks by transforming them into
manageable, automated processes.
- 44%
of cybersecurity experts believe that its ability to streamline and
improve secrets detection will be crucial in preventing data leaks,
emphasizing that the most effective agentic AI-driven security solutions
are those with contextual awareness for making informed decisions.
"It's
fascinating to follow the industry's measured, yet rapid adoption to Agentic
AI. Many interpretations and modalities of 'agent' exist, from simple chatbots
to complex workflow automations to true autonomous agents," says Amir
Kazemi, Director of Product Marketing at Cycode. "Our data underscores
that educating the market on what agentic AI truly is, why it matters for
AppSec, and its tangible value is paramount right now. Cycode is committed to
leading this charge, empowering security teams and developers the ability to
sense, reason, and act with context through agentic AI solutions."
As adoption
accelerates, Cycode remains at the forefront, helping organizations navigate
this shift with an AI-Native Security Platform that strikes the right balance
between innovation and oversight. Cycode's agentic AI framework recently
introduced autonomous AI Teammates that
empower developers and security teams. Cycode redefines secure software
development and elevates modern security practices by fostering seamless
collaboration and enabling real-time, context-aware remediation.