Cloud Native

GenAI Generated Code is Insecure by Default—Jit is Fixing That with AI Agents

0

Generative AI (GenAI) has revolutionized software development, accelerating code generation and boosting productivity. In a world where developers are moving at lightning speed—often powered by GenAI tools like GitHub Copilot and Cursor—application security (AppSec) teams are struggling to keep pace.

Recent research shows that around 70% of all code being written today is generated by GenAI—and about 30% of that code contains security vulnerabilities,  that’s a staggering amount of potential risk.

The security gap is widening, and traditional approaches to vulnerability management just can’t keep up.

“By default, the code generated by GenAI is not secure,” warns David Melamed, Co-Founder and CTO of Jit, “Developers, especially junior ones, often deploy this code without fully understanding the risks.”

And with developers vastly outnumbering security professionals, this imbalance puts organizations at serious risk.

Jit, a modern security platform, is addressing this challenge head-on by introducing AI agents to assist AppSec teams. In this exclusive video interview with Melamed, we dive into the announcement made by Jit and explore how these AI agents will transform the future of application security.

“We’re building the AppSec teams of the future,” says Melamed. “And that future is a collaboration between humans and AI agents. We will supercharge the AppSec teams by providing AI agents that will do all the busy work and let the AppSec teams focus on remediation, on what really matters from the business.”

The Impact of Jit’s AI Agents on Organizations

Jit’s AI agents are poised to revolutionize the way AppSec teams operate. By leveraging the company’s knowledge graph, which contains extensive metadata about the organization’s engineering, cloud, and security data, these AI agents can accurately assess business risks and prioritize remediation efforts. As Melamed states, “Those agents will actually do most of the work, and the only thing the human teams will do is decide whether or not to fix something.”

Moreover, these AI agents will also play a crucial role in helping developers understand threat modeling and implement security measures proactively, fostering a culture of security by design.

Jit’s AI agents are designed to seamlessly integrate into the existing workflows of AppSec teams. Equipped with a chat interface, these agents can be accessed through various communication platforms, such as Slack, and even directly within pull requests. This ensures that AppSec teams can interact with the AI agents wherever they work, making the entire vulnerability management process more efficient.

Unlike traditional vulnerability management tools, which follow a predefined workflow, Jit’s AI agents can adapt their workflow based on the current inputs and available information. This dynamic approach allows the agents to assess the severity of vulnerabilities more accurately, gather additional information as needed, and even run tools to verify the exploitability of a given issue. As Melamed puts it, “That’s a revolution.”

The Future of Jit’s AI Agents

Jit’s AI agent platform is just the beginning. The company plans to launch more specialized agents in the near future, focusing on areas such as cloud security and compliance. By staying closely aligned with customer needs and feedback, Jit is committed to building a comprehensive suite of AI agents to address the unique security challenges faced by organizations in the AI era.

With the introduction of AI agents, Jit is paving the way for a new era of application security. By empowering AppSec teams to focus on what truly matters – remediation and improving security postures – Jit’s AI agents will enable organizations to embrace the power of AI-generated code while mitigating the associated risks. As the adoption of AI-based solutions continues to grow, Jit’s innovative approach ensures that businesses will be well-equipped to navigate the evolving security landscape with confidence.

Guest: David Melamed
Company: Jit
Show: An Eye on AI

Platform9 Releases Free Private Cloud Director Community Edition

Previous article

New Calico Release Simplifies Microsegmentation and Boosts Kubernetes Visibility

Next article