In this RAISE Summit fireside chat, Peter McKay (CEO, Snyk — pronounced “sneak”) explains how the developer-security pioneer is becoming an AI-first company with its new AI Trust Platform. He lays out why embedding security directly into rapidly accelerating, AI-driven development workflows (copilots, agents, MCP, etc.) is now non-negotiable—and how Snyk aims to secure everything from AI-generated code to LLMs, pipelines, agents, and integrations without slowing builders down.
Key discussion points include:
- From DevSecOps → AISecOps: Applying a decade of developer security to the AI stack—guardrails, red teaming, and runtime controls for agentic systems.
- Guardrails for codegen: Catching and fixing issues at the point of creation in Copilot/Cursor/Windsurf; auto-remediation to drain long-tailed vuln backlogs.
- Rising attack surface: Code generators can introduce ~40% more vulnerabilities; new threats span prompt injection, data poisoning, model manipulation, and MCP integration risks.
- Orchestration & speed: Build security into the dev flow—keep developers fast while giving security teams visibility, policy, and control by default.
- Evolving “developer” definition: Domain experts (marketing, finance, ops) can now build apps/agents—so security must be automatic and embedded, not taught after the fact.
- Roadmap (12–24 months): Deeper model/pipeline protections, secure agent guardrails, MCP-aware controls, and expanding auto-fix fueled by Snyk’s vulnerability intelligence.
- M&A as an accelerator: 12 acquisitions to date (incl. Invariant Labs)—prioritizing team+tech buys that integrate natively into Snyk’s unified platform.
- Long-term vision: Autonomous security—like spellcheck for code and agents—“built-in by default,” so organizations can chase AI speed without sacrificing trust.
Want to secure AI-generated code, LLMs, and agentic apps without slowing your teams down? Watch the session—and like, comment, and subscribe for more hands-on AISecOps insights from the RAISE Summit.