Security

Application security must shift from finding bugs to fixing them

As AI makes vulnerability detection commoditized, vendors will compete on how much remediation work they automate for engineering teams.

Omega Editorial· September 17, 2026· 3 min read

The application security market is reaching an inflection point where simply identifying vulnerabilities no longer differentiates products. As AI capabilities democratize advanced detection across vendors, the competitive battleground is shifting to what happens after the scan completes.

Roni Fuchs, co-founder and CEO of Legit Security, argues that security tools have traditionally stopped at the same place: they connect to your systems, generate a list of findings, and leave your team to handle prioritization, ownership assignment, and remediation. That model is becoming unsustainable as AI accelerates both code creation and attacker capabilities.

The detection commodity trap

When multiple security products can produce similar vulnerability lists, the tool that wins is the one that helps complete the work after detection. This shift is most visible in application security, where CISOs face mounting backlogs, constrained budgets, and little prospect of adding headcount.

Consider a vulnerable open-source component used across several applications. Different tools may flag it in multiple locations, creating separate tickets for one shared problem. Before any fix can proceed, someone must determine where the component is deployed, whether attackers can reach the vulnerable code path, which team owns it, and how to prioritize it against other risks. Counting alerts reveals almost nothing about this engineering effort.

Why it matters

The window to address real vulnerabilities is shrinking from both directions—AI helps developers ship code faster while simultaneously helping attackers find weaknesses more efficiently. Security teams that continue relying on detection-only tools will face exponentially growing remediation backlogs that manual processes cannot resolve. Organizations need platforms that can carry fixes through their actual development workflows, not just identify problems.

From scanning to orchestration

Fuchs, who came up as a developer before founding Legit Security, emphasizes that organizational context is becoming part of the product itself. Source code alone does not reveal deployment patterns, team ownership, or business impact. His company has spent years mapping these relationships across what he calls "the software factory."

For AI agents that prepare and validate fixes, these maps help transform a proposed patch into a change that can navigate a real organization. While code-writing models are widely available, each customer's map of applications, teams, and environments must be built specifically for them.

The product's responsibility should extend from initial finding through fix selection, change preparation, developer assignment, and result verification. Scanners remain essential information sources within this process, but customers should expect platforms to automate work their teams currently bridge manually.

Human accountability remains central

Automation does not eliminate human responsibility. Engineers and security leaders remain accountable for what reaches production, including agent-prepared changes. They need reviewable evidence: what changed, why it was prioritized, which checks ran, and what remains uncertain.

Application security teams are evolving into managers of security agents, translating their judgment into policies that define which fix classes agents may prepare, what evidence is required, and when escalation is necessary. The quality of these rules and visibility into their application become part of what customers are purchasing.

Fuchs recommends buyers test for this capability during trials. Follow a real vulnerability through to a verified change in the affected environment. Observe how much investigation, coordination, and review your team still handles. Ask where work stops when the system lacks information. A demo ending with a generated patch leaves critical questions unanswered: was the fix deployed, and did it actually reduce risk?

These details were first reported by CTech, where Fuchs published his analysis as an opinion piece.

#application security#vulnerability management#security automation#ai agents#devsecops#legit security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 4 min read

Three-Quarters of CISOs Use Legacy Controls for AI Risks

New survey data reveals most enterprises are securing AI workflows with tools built for earlier threats, while entry points multiply without IT oversight.

Via AI Watch · Sep 17, 2026
Security· 3 min read

Frontier AI Models Shift Cybersecurity From Finding to Fixing Flaws

NTT DATA warns that advanced AI is democratizing sophisticated cyberattacks, forcing enterprises to rethink vulnerability management priorities.

Via AI Watch · Sep 17, 2026
Security· 3 min read

Spain Reports First Data Breach by Autonomous AI Agent

The country's data protection authority says an AI system independently logged in, exploited a vulnerability, and altered personal records.

Via AI Watch · Sep 17, 2026