📊 Key Data
  • $100 billion: Projected market value of application security by next decade.
  • New AI-BOM feature: Provides transparency into AI models and components used in applications.
  • Agentic SAST triage: Uses AI to automatically analyze vulnerabilities, reducing alert fatigue.
🎯 Expert Consensus

Experts would likely conclude that Mend.io's new capabilities represent a strategic shift toward securing the entire AI application lifecycle, addressing dynamic runtime threats while leveraging AI to improve vulnerability prioritization and reduce operational friction for security teams.

3 days ago
Beyond the Hype: Mend.io Arms Enterprises for the Real Risks of AI Apps

Beyond the Hype: Mend.io Arms Enterprises for the Real Risks of AI Apps

BOSTON, MA – July 28, 2026 – The proliferation of Artificial Intelligence in software development presents a classic dilemma for the modern enterprise: innovate at an unprecedented pace or manage an explosion of new, poorly understood risks. For security teams already struggling to keep up, AI has become both a powerful tool and a formidable threat. In a significant move to address this gap, application security leader Mend.io has announced a suite of new capabilities designed to secure the entire AI application lifecycle, from the developer’s first line of code to the unpredictable environment of live production.

The enhancements to its Mend AI and Mend AppSec platforms are not merely incremental updates; they represent a strategic pivot to confront the unique challenges posed by AI-powered applications, including a new class of threats that traditional security tools were never designed to see.

The New Frontier of Risk: Securing AI at Runtime

For the past decade, the mantra in application security has been to “shift left”—finding and fixing vulnerabilities as early as possible in the development process. While essential, this approach is fundamentally insufficient for AI applications. The most potent threats, such as prompt injection, jailbreaking, and sensitive data exfiltration through Large Language Models (LLMs), do not exist in static code. They emerge dynamically during runtime, based on user interactions and the behavior of the AI model itself.

Mend.io’s announcement directly targets this blind spot by extending protection into runtime. The platform now offers real-time guardrails, deployable either within the application or as a standalone proxy, that inspect prompts and responses for malicious activity. This acts as a crucial defense layer against an attacker manipulating an AI agent into executing unintended commands, leaking confidential data, or bypassing security policies. Furthermore, the new capability scans AI agent configuration files for common weaknesses like excessive permissions or credential exposure, hardening the application before it even faces external threats.

“Organizations need to quickly understand what actually affects their applications, respond when new threats emerge, and protect an entirely new AI application attack surface,” said Asaf Saar, EVP and Chief Product Officer at Mend.io. “Mend.io is bringing those capabilities together so security teams can focus on what matters.”

This move into runtime protection is complemented by the creation of an AI Bill of Materials (AI-BOM), providing transparency into the AI models, agents, and frameworks used in an application. For security and governance teams, this is a critical step toward managing the otherwise opaque supply chain of AI components.

Taming the Noise: AI-Powered Triage and Contextual Prioritization

While AI introduces new risks, it hasn't erased existing ones. Security teams remain inundated with alerts from traditional Static Application Security Testing (SAST) and Software Composition Analysis (SCA) tools. A significant portion of these alerts are often false positives or low-impact vulnerabilities, leading to severe alert fatigue and slowing down development.

Mend.io is leveraging AI to solve this very problem. Its new “Agentic SAST triage” uses an AI agent to automatically analyze findings, distinguish true vulnerabilities from noise, and provide context on how a flaw might be exploited. This allows human teams to bypass hours of manual investigation and focus their efforts on genuine threats. According to one security analyst, “For years, AppSec has been about finding more things. The paradigm shift is now about finding the right things and fixing them instantly. Tools that can't separate the signal from the noise are becoming obsolete.”

This focus on prioritization is further enhanced by “Contextual Project Classification.” The feature uses AI to analyze a codebase and determine its business function—for example, whether it processes payments, handles healthcare records, or stores personally identifiable information (PII). This allows risks to be prioritized based on their potential business impact, not just a generic technical severity score. An otherwise moderate vulnerability in a non-critical internal app can be deprioritized, while the same flaw in a customer-facing payment portal is immediately flagged as urgent. This business-aware context is also applied to the company’s accelerated zero-day response, enabling organizations to instantly trace an emerging threat's impact on their most critical systems.

A Crowded Field Navigating the AI Security Gold Rush

Mend.io’s announcement does not happen in a vacuum. It comes as the entire application security market, projected to be worth over $100 billion by the next decade, pivots aggressively toward AI. Competitors like Snyk, Checkmarx, and Veracode are all racing to integrate AI into their platforms, offering features like AI-driven code fixes, AI-assisted vulnerability detection, and their own forms of runtime protection.

The common thread across the industry is the recognition that securing AI requires a new playbook. The focus is shifting toward autonomous, “agentic” security that can operate at machine speed, a deep integration into developer workflows, and a holistic view that covers the entire software supply chain—from open-source dependencies and AI-generated code to the container images they are packaged in. Mend.io’s expanded SCA capabilities, which now detect malicious open-source packages within container images, directly address this growing supply chain threat.

By branding itself as an “AI-Native AppSec Platform,” Mend.io is making a clear statement about its strategic direction. The goal is to be perceived not just as a tool that secures AI, but as a security platform built with AI at its core, capable of understanding and defending against the complex, dynamic nature of modern applications.

The View from the Trenches: A Shift in Security Posture

For enterprises on the front lines, these advancements promise a significant shift in operational reality. The ability to automate triage, prioritize based on business context, and protect against entirely new threat vectors helps transform security teams from gatekeepers into enablers of secure innovation.

This impact is already being felt by early adopters. “Mend.io has been with us for years, long before AI security... Now Mend.io has helped us grow our program to face the risks AI brings with generated code and in the AI components themselves,” said Alen Pešikan, Principal Software Engineer at Span Software and AI Solutions. “SPAN is able to keep up with a changing attack surface without wearing out our teams. We can see where the exposure sits, focus our resources where they count, and react fast as things change.”

This testimony highlights the ultimate goal of the new security paradigm: building resilience without creating friction. As organizations increasingly rely on AI to build and run their most critical applications, the guardrails protecting them must be just as intelligent, adaptive, and scalable. By extending protection from the first line of code to the final runtime interaction, the industry is signaling a mature, full-spectrum approach necessary to harness AI's promise without succumbing to its perils.

Topics & Related

Sector:
Cybersecurity
AI & Machine Learning
Theme:
Artificial Intelligence
Threat Landscape
Event:
Product Launch

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 44826