Opens in a new tab
vmblog logo 2024 wht (updated)

The Future of AI AppSec with Stackhawk

Share: 

David Marshall | Published: December 30, 2025

vmblog-2026-prediction-series   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive.  

By Scott Gerlach, CSO and Co-Founder of StackHawk

As we look forward to 2026, the landscape of AppSec is poised for significant transformation. Emerging trends suggest a shift from traditional metrics and tools to a more nuanced understanding of security coverage, driven by a need for foundational visibility across the attack surface. The convergence of advanced technologies with AI will reshape how security assessments are conducted, elevating the importance of strategic thinking and influence among security professionals.

As AppSec continues to assert its relevance within the broader organizational framework, the role of security leaders will evolve to bridge the gap between technical realities and business imperatives. Below are four pivotal predictions that highlight the path forward for organizations alike as they navigate these changes. 

1. From Activity Metrics to Coverage Intelligence

The prediction: By the end of 2026, “how many scans” and “how many findings” become irrelevant KPIs. The new question is “what percentage of our attack surface is actually covered, and by what?” This requires foundational visibility that most orgs don’t have. ASPM was supposed to solve this but only managed the symptoms (alert fatigue) not the disease (coverage gaps). The single pane of glass promise dies again because it was always stained glass-aggregating incomplete data more prettily doesn’t make it complete. More testing and aggregating tools will go deeper into providing that visibility, ideally from code. 

2. The Great AI AppSec Consolidation

Two convergences happen simultaneously. First, DAST evolves into multi-stage testing-providing runtime feedback in dev lifecycle while AI-powered techniques add creativity and validation out-of-band. Second, the wave of standalone “AI AppSec” startups get acquired or absorbed by established players. AppSec teams can’t support another tool category. The market matures from “AI for security” hype to “security that uses AI where it actually helps.” 

3. Technical Depth in Security Hires Becomes Table Stakes

The best AppSec hire in 2026 isn’t the person who can write the exploit-it’s the person who can explain to the PM why the roadmap needs to change. AI commoditizes technical execution, so it’s judgment and influence that become the scarce resources. Meanwhile, teams that “build everything with AI” in 2026 will be drowning in operational debt by 2027. The new vendor value proposition isn’t “we built it so you don’t have to”-it’s “we maintain it so you don’t have to.” 

4. AppSec Earns Its Seat at the Table

AI fundamentally changes software development. The only people who can articulate the risk implications to business leaders are AppSec professionals who understand both the technical reality and business context. This creates an opportunity-AppSec leaders who can translate become strategic advisors. But operationally, day-to-day AppSec work reports to whoever owns delivery velocity (Product/Engineering), not the security org. CISOs become more like regulators than operators. 

## 

ABOUT THE AUTHOR 

Scott Gerlach is Co-Founder & CSO of StackHawk, the AppSec intelligence platform reimagining application security for AI-driven development. A committed security executive, Gerlach has over 20 years of experience in information security, including security processes, procedures, policies, and compliance. He successfully helped guide and manage two prior companies through acquisition, transition, and IPO.