Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

Develop at AI Speed. Ship with Confidence.

Type Webinar
Organization Sonatype

Webinar Description

Key Takeaways

  • Focuses on application security practices adapted for generative AI development environments
  • Addresses AI model governance, open source dependency management, and software supply chain security
  • Features AWS Kiro and Sonatype Guide as tools for secure AI operationalisation
  • Designed for security professionals, DevOps engineers, developers, and technology leaders
  • Includes live demonstration of governance and compliance workflows

Introduction

Sonatype and AWS are presenting a webinar titled “AppSec Best Practices for the AI Era,” examining how organisations can maintain robust security and compliance standards while adopting generative AI in their software development workflows. The session targets application security professionals, DevOps engineers, software developers, and technology executives who are navigating the complexities of AI-driven development. As generative AI accelerates code production and enables new capabilities, it simultaneously introduces challenges around model governance, open source risk management, and supply chain integrity that traditional security approaches were not designed to address.

About This Event

This virtual webinar combines educational content with practical demonstration, offering attendees guidance on securely operationalising generative AI within enterprise environments. The session features a live demonstration using AWS Kiro, an AI development tool, alongside Sonatype Guide, a platform designed for AI governance and security management. The format emphasises actionable insights rather than theoretical discussion, with the goal of helping organisations implement security controls that do not impede developer productivity.

Governing AI Models and Open Source Dependencies

A central theme of the webinar is the governance challenge that emerges when AI-generated code introduces open source components at scale. Generative AI tools can suggest or incorporate dependencies faster than security teams can evaluate them, creating potential blind spots in vulnerability management and licence compliance. The session addresses how organisations can establish visibility into these dependencies and implement automated policy enforcement that operates at the pace of AI-assisted development.

Model governance extends beyond code dependencies to encompass the AI models themselves. Organisations deploying machine learning models must consider provenance, training data compliance, and ongoing monitoring for drift or unexpected behaviour. The webinar explores frameworks for managing these concerns within existing DevSecOps workflows.

Software Supply Chain Security in AI Development

Software supply chain security has become a board-level concern following high-profile incidents affecting widely used components. When generative AI enters the development process, the attack surface expands in ways that require updated security strategies. AI models may suggest outdated libraries, introduce transitive dependencies with known vulnerabilities, or incorporate components with incompatible licences.

The webinar examines how security teams can maintain supply chain integrity without creating friction that drives developers toward shadow IT solutions. This balance between security rigour and developer experience represents one of the more persistent tensions in modern application security, and generative AI amplifies both the risks and the productivity benefits at stake.

Who Should Attend

The session is designed for professionals responsible for securing software development environments, particularly those working within or alongside AWS infrastructure. Application security specialists will find relevant content on adapting existing practices for AI-augmented workflows. DevOps engineers and platform teams can expect guidance on integrating governance controls into CI/CD pipelines. Product managers and technology executives may benefit from the strategic perspective on balancing innovation velocity with risk management obligations.

Organisations in regulated industries or those subject to emerging AI compliance requirements will find the compliance and policy enforcement content particularly relevant as regulatory frameworks around AI continue to develop globally.

Practical Value for Security Teams

The inclusion of a live demonstration distinguishes this webinar from purely conceptual discussions of AI security. Attendees will observe how AWS Kiro and Sonatype Guide function together to provide visibility into AI-generated code, enforce organisational policies automatically, and surface compliance issues before they reach production environments. This practical focus aims to bridge the gap between security principles and operational implementation.