
Episode #14
Why AI Code Review Will Replace Human Review Faster Than You Think
Jim Manico thinks the era of human code review is ending, and that clinging to it will hurt your company. The founder of Manicode Security returns to explain why AI didn't kill AppSec education but supercharged it, why vague prompting on frontier models turns companies into "token furnaces," and why prompt injection is the one genuinely new vulnerability class of the AI era. He walks Chris and Robert through his full AI coding workflow, from reverse engineering an architecture file to security rules and planning-mode build plans that make AI output deterministic. The three debate whether AI will finally eliminate SQL injection, whether AppSec vendors can survive without integrating cyber models, and when humans still need to step in: the moment an agent tries something its policy doesn't allow. Plus: the one habit every security leader should teach developers now. This episode is sponsored by Security Compass . Make modern software development secure, consistent, and provable. About Security Compass AI writes code faster than anyone reviews the design. Threats do not wait for an annual assessment. Security Compass models threats continuously and turns them into requirements developers act on, not a report read after ship. → Learn more about securing the AI-DLC with Security Compass This episode is sponsored by Corgea . Design it. Build it. Ship it. Corgea secures it. About Corgea Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely. → Learn more about Corgea Connect with Jim Manico: → Jim Manico on LinkedIn Mentioned in this episode: → Manicode Security → Manicode Forge → OWASP Artificial Intelligence Security Verification Standard (AISVS) → OWASP AISVS on GitHub → Claude Code → Ollama Follow the Application Security Podcast: ➜ Home: appsecpodcast.com ➜ X: @AppSecPodcast ➜ LinkedIn: The Application Security Podcast ➜ YouTube: @ApplicationSecurityPodcast ➜ Instagram: @appsecpodcast ➜ Facebook: Application Security Podcast Chapters: 00:00:00 - Cold open: the era of code review is ending 00:00:47 - Meet Jim Manico 00:01:03 - Welcome and what gets Jim away from screens 00:05:29 - How AI changed developer security education 00:07:03 - Teaching developers to use AI well 00:09:26 - Where AI and AppSec stand: the token furnace 00:12:08 - Separating signal from hype 00:14:24 - Integrate with cyber models or die: the future of AppSec tools 00:18:34 - Are AI coding assistants creating new vulnerabilities? 00:20:02 - Prompt injection: the one truly new class 00:21:15 - Will AI eliminate the OWASP Top 10? 00:24:18 - Local models and Apple's hardware edge 00:28:32 - Jim's AI coding workflow, step by step 00:33:57 - The end of human code review 00:38:31 - Can we trust AI code review, and when do humans step in? 00:44:56 - Where companies really are with AI 00:47:02 - One change for security leaders: planning mode 00:48:19 - Wrap up

