
AI Security: OWASP Meets Global Standards
transcript
show notes
AI security has no shortage of standards — the problem is turning them into something a team can actually use. Rob van der Veer has spent 34 years in AI and security, founded the OWASP AI Exchange, and created MOSAIC, the agreement that brought eight standards bodies together with SANS to stop the fragmentation. Rob explains what responsible AI really means, what the EU AI Act actually asks of you, and why most AppSec teams are still missing the point on AI-generated code. We also get into agentic red teaming, what happens when agents quietly exceed their scope, and whether AI finally levels the playing field between attackers and defenders. If you build software with AI in it — or with AI — this one is worth your time.
This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.
About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
→ Learn more about Corgea
Connect with Rob van der Veer:
→ Rob van der Veer on LinkedIn
→ OWASP AI Exchange
→ MOSAIC
Mentioned in this episode:
→ OpenCRE
→ Luna and the Magic AI Paintbrush
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast
Chapters:
00:00 Cold open — don't be surprised when the AI breaks out of the cage
01:15 Meet Rob van der Veer: music, cycling, and the Hoodoo 500
05:24 Defining responsible AI
07:41 Fairness, protected attributes, and transparency
09:34 The EU AI Act and what regulation actually asks of you
11:27 How AI changes every part of software development
13:23 Where responsibility lands
15:20 You're not defending your own data center
17:19 What traditional AppSec teams consistently miss about AI
18:18 Finding vulnerabilities in AI-generated code
19:19 Too many standards — and using AI to write them
20:51 MOSAIC: eight standards bodies, one agreement
22:09 One machine-readable taxonomy with OpenCRE
23:06 Can AI level the field between attackers and defenders?
25:59 When AI security becomes security theater
26:56 What agentic red teaming actually looks like
29:44 When agents exceed their scope
32:43 Luna and the Magic AI Paintbrush
33:40 Do we sandbox the agents?
34:40 Guardrails without killing creativity
36:39 Skill atrophy when AI is your only way forward
40:04 "How do we hit this quarter?" and the pressure to ship
43:16 Everyone is selling agentic security
45:07 Key takeaways and where to start with the AI Exchange
47:12 Closing thoughts
Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast