This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Don’t Trust the Vibes: Securing AI-Generated Code

Download resources

About this session

Two speakers from Snyk, introduced only as "Mike" (a part-time computer science professor) and Matt Bartley (Snyk's go-to-market lead for AI), argue that AI-generated code stays roughly 45 percent insecure even though it almost always runs, because large language models learn from tutorials that teach syntax, not security. Mike live-demonstrates a one-shot "vibe coded" student-assistant chatbot that leaks confidential grades through prompt injection despite an explicit instruction not to, and shows that hardening the system prompt, sanitizing input and re-verifying output with a second model each reduce but do not eliminate the risk. Matt broadens the discussion to agentic AI risk generally: developers are running multiple coding agents, MCP servers and skills on their endpoints with little oversight, so security teams need an inventory of every model, MCP and skill in use, a unified policy engine or AI gateway to enforce allow-lists, human-in-the-loop remediation rather than autonomous fixing, and continuous automated red-teaming of AI-assisted applications.

Generative AI has collapsed the barrier to writing code—you no longer need to know what a SQL injection is to ship a working application. That’s the promise. It’s also the problem.
Using a real, 100% AI-generated chat application as an example, this session explores how AI-generated code can introduce vulnerabilities, why prompt hardening alone isn’t enough, and how prompt injection and insecure code can expose sensitive data. We’ll cover practical techniques like output validation, input sanitization, and better prompting patterns to reduce risk.
The session then expands to the broader AI security landscape: automated attacks, agentic development, and securing AI applications in production. Attendees will leave with a practical framework for evaluating AI-generated code, prompting more securely, and managing AI risk across the software development lifecycle.

Key takeaways

  • Do not trust a strong system prompt alone to secure an AI-generated app; pair prompt hardening with input sanitization and output validation, since roughly 45% of AI-generated code stays insecure even when it works.
  • Re-verify sensitive model output with a second model (or the same one run again) before it reaches the user; it catches prompt-injection leaks that the original system prompt alone misses.
  • Build and maintain an inventory of every model, MCP server and skill running on developer endpoints before writing any AI governance policy; you cannot govern what you have not counted.
  • Start AI security enforcement with an allow-list, not a block-everything default, and use volunteer teams to tune the noise level before rolling it out organization-wide.
  • Keep a human in the loop for AI-proposed remediation rather than letting an agent auto-fix code, and run continuous automated red-teaming against AI-assisted applications.

Speakers

Michael Biocchi
Michael Biocchi
Lead AI Activation & Education Manager · Snyk
Michael Biocchi has completed his PhD and has received his Masters of Science as well as his Bachelor of Computer Science. He is also a Certified Information Systems Security Professional (CISSP). Michael has taught in the education sector for 15+… Read moreRead less

Michael Biocchi has completed his PhD and has received his Masters of Science as well as his Bachelor of Computer Science. He is also a Certified Information Systems Security Professional (CISSP). Michael has taught in the education sector for 15+ years, teaching a variety of computer science (Cybersecurity, Software Engineering, etc.) courses at a number of different institutions across Canada. He has an award-winning Udemy course with over 100,000 students teaching about Security Awareness Training.

Matt Bartley
Matt Bartley
GTM Lead - AI · Snyk
Matt Bartley began his career as a networking engineer at Hewlett Packard Enterprise (HPE) focused on projects for the US Gov sector. Since 2017, he has worked extensively in the fields of Cloud and Application Security. Matt has helped take two… Read moreRead less

Matt Bartley began his career as a networking engineer at Hewlett Packard Enterprise (HPE) focused on projects for the US Gov sector. Since 2017, he has worked extensively in the fields of Cloud and Application Security. Matt has helped take two startups to a successful exit and helps lead the GTM for Snyk’s AI Security Platform.

Resources

Photos

Tags

More from GoSec 2026

Also from Michael Biocchi

On the same topic