AI writes the code. But who checks it, and who is accountable when it goes wrong? In this episode, Matthias is joined by two colleagues: Guillaume Teixeron, bringing 20 years of experience on the product side of identity and authentication, and Jonathan Care, KuppingerCole Analysts' Director of Practice AI. Together they tackle the security gap opening up between how fast AI generates code and how slowly organizations are catching up on assurance, provenance, and accountability.

Key Topics:

✅ AI in software development: from hype to structural baseline — but governance is still improvised
✅ Three tectonic shifts in AppSec: provenance, scale, and non-human identity
✅ Why organizations have industrialized code production but not code assurance
✅ The core question: can you trust AI to verify AI-generated code?
✅ Agent autonomy in production pipelines — the next flashpoint nobody has resolved yet
✅ How regulation (CRA, NIS2, DORA) will settle the provenance argument before the market does

"We have industrialized code production. We have not industrialized code assurance." Jonathan Care on why the security control set was built for human-authored code moving at human speed — and neither assumption is true anymore.

📅 Join KuppingerCole Analysts at the AIdentity & NHI Impact Day in Munich this October — where the accountability and provenance questions raised in this episode will be front and center.

Podden och tillhörande omslagsbild på den här sidan tillhör KuppingerCole Analysts. Innehållet i podden är skapat av KuppingerCole Analysts och inte av, eller tillsammans med, Poddtoppen.