AI is building your software. Who's making the security decisions?

Oct 5, 2026

AI coding assistants are changing how software gets built. Traditional AppSec tools focus heavily on scanning the final code artifact, but as AI agents move from simple code dependencies to autonomous decision-makers and execution paths, traditional security controls enter the process too late.

In this session, Ashley Delonso (Senior Product Marketing Manager at Mend.io) and Gil Rigbi (General Manager at Mend AI) break down the evolution of AI supply chain risks. Discover why old payloads are entering through entirely new entry points, how to move from detection controls to decision influence, and the five practical disciplines required to secure software in an AI-native world.

Key Timestamps

00:10 – Introduction and speaker roles

01:08 – The shift in software supply chain risks

02:42 – AI supply chain threat categories

05:14 – Old payloads, new entry points

06:36 – The 3 roles of AI: Dependency, decision-maker, and execution path

08:42 – The core SDLC assumption: Human vs. AI decision-making

11:08 – Detection controls vs. decision influence

13:28 – What is slop squatting?

17:13 – Scenario: AI agents and the lack of security context

20:05 – Threat hunting & the loss of context in root cause analysis

22:20 – Models, MCP servers, and autonomous permissions

23:21 – The leadership test: Mapping AI assets and access

27:28 – The interaction layer: Bridging the code layer and the AI layer

31:08 – 5 disciplines to secure AI-driven software development

34:31 – Key takeaways: Securing AI actions and decisions

36:25 – Live Q&A and additional resources