Cookies Notice
This site uses cookies to deliver services and to analyze traffic.
📣 Introducing AI Threat Modeling: Preventing Risks Before Code Exists
Unified risk and vulnerability management across application, infrastructure, and code quality scanners, with code-to-runtime actionable context
Automated security controls validation and assurance based on your organization’s SDLC policies, with actionable context from your CMDB
Risk Graph policy engine and developer’s guardrails at every phase: design, development (pull request), and delivery (build/deploy)
In a recent interview, Apiiro sat down with Thomas Dohmke – former GitHub CEO and now Strategic Advisor to Apiiro – to discuss the impact of AI on software development, and what it specifically means for application security.
From coding on a Commodore 64 to leading one of the world’s most influential developer platforms, Thomas has had a front-row seat to every major shift in software development. And according to him, we’re now entering the most transformative era yet: one where AI is not just assisting developers, it’s generating code at unprecedented scale.
Thomas emphasizes that AI-assisted coding represents a structural shift, not just an incremental improvement.
But as velocity increases, so does complexity: “The amount of code that’s being generated is increasing dramatically.”
More code means:
Security teams can’t rely on traditional, reactive models to keep up.
Thomas discusses the inefficiency of discovering issues late in runtime, where remediation is slower, more expensive, and more disruptive. In short, prevention must replace reaction.
“So you have a win-win.” Developers maintain velocity, security ensures meaningful risks don’t reach production, and the business avoids unnecessary friction.
Safeguarding AI before code generation is the most feasible path to prevention at enterprise scale. AI-generated code introduces new layers of risk:
“You have to understand your architecture. You need to safeguard AI before code generation.” Thomas underscores that organizations must understand their software architecture deeply enough to secure AI-driven systems proactively, and not just after deployment.
AI-assisted exploitation is real, attack surfaces are expanding, and security must evolve just as fast as development. As attackers increasingly automate reconnaissance and exploitation, security defenses too must become more autonomous, contextual, and proactive.
Thomas envisions the future of application security looking like:
“We are transforming into a model of orchestrating agents; how can we unblock them when they run into issues, and how can we use a Guardian Agent to make sure the code is shipping in a secure way?
Software development has entered a new era, and the organizations that will thrive are those that:
That’s the vision Thomas Dohmke brings to Apiiro – and the standard modern enterprises must adopt to stay ahead.
This site uses cookies to deliver services and to analyze traffic.