#S2.10 When Coding Agents Ship at Machine Speed, AppSec Has to Move Into the Loop - Jan Brennenstuhl

S.02 EP.10 - When Coding Agents Ship at Machine Speed, AppSec Has to Move Into the Loop - Jan Brennenstuhl

August 13, 2026

In this episode of Beyond Vibe Coding, Sebastian Heide-Meyer zu Erpen and André Neubauer talk with Jan Brennenstuhl about application security in the age of agentic engineering. Jan explains how his own workflow already depends on long-running local agents, why the surrounding harness matters more than the frontier model, and why spec-driven approaches can be useful when agents make greenfield projects grow very quickly.

The main conversation focuses on a structural shift in AppSec. Jan argues that traditional security gates, delayed scanner feedback, and ticket-based remediation cannot keep up with machine-speed code generation. Security has to move into the agent loop, into platform defaults and into standardized engineering infrastructure so that agents replicate secure patterns instead of every local workaround and architectural exception.

The episode closes with a prediction: verification of intent becomes the premium engineering capability. As implementation gets cheaper, the valuable work shifts toward understanding what should be built, proving that it was built correctly, and designing engineering systems that can safely absorb autonomous change.

Links and References

Jan Brennenstuhl: https://www.janbrennenstuhl.eu/AppSec in the Age of Agentic Engineering: https://www.janbrennenstuhl.eu/appsec-agentic-engineering/Shift Down: Why Agentic Engineering Demands Platform-Level Security: https://www.janbrennenstuhl.eu/shift-down-appsec/Hugging Face Security Incident Disclosure, July 2026: https://huggingface.co/blog/security-incident-july-2026OpenAI and Hugging Face Security Incident Statement: https://openai.com/index/hugging-face-model-evaluation-security-incident/AGNTCon + MCPCon Europe 2026: https://agntconmcpconeu26.sched.com/