---
title: "San Francisco Secure Software and AppSec Summit 2026: The Next AppSec Operating Model"
url: https://daily.dev/posts/san-francisco-secure-software-and-appsec-summit-2026-the-next-appsec-operating-model-fcvwfzfna
source_url: https://blog.gitguardian.com/san-francisco-secure-software-and-appsec-summit-2026
type: article
source: "GitGuardian"
published: 2026-05-18T14:02:25.208Z
updated: 2026-05-18T14:02:54.416Z
tags: ["security", "ai-agents", "devsecops", "appsec", "sbom"]
reading_time: 10
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# San Francisco Secure Software and AppSec Summit 2026: The Next AppSec Operating Model

**[GitGuardian](https://daily.dev/sources/gitguardian)** · 10 min read · 0 upvotes · 0 comments

## Summary

A recap of the San Francisco Secure Software and AppSec Summit 2026, covering key themes from practitioner sessions. Topics included securing autonomous AI agents (treating prompt injection like arbitrary code execution, scoping agent permissions, requiring revocable identities), decommissioning stale infrastructure as a security control, the limited effectiveness of SBOMs for production risk reduction, and the future of AppSec shifting from manual code review toward control plane engineering. The overarching message: AppSec is moving from a review function to an architectural layer that enforces constraints at machine speed, with ownership accountability and reversibility as the new security boundaries.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://blog.gitguardian.com/san-francisco-secure-software-and-appsec-summit-2026>

## Similar posts on daily.dev

- [BSides SF 2026: Looking At Security Beyond The Next Big Bet](https://daily.dev/posts/bsides-sf-2026-looking-at-security-beyond-the-next-big-bet-b6e7cm3ui) · GitGuardian · 0 upvotes · 0 comments
- [SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top](https://daily.dev/posts/snowfroc-2026-secure-defaults-real-trust-and-a-better-layer-on-top-ybeigipxm) · GitGuardian · 0 upvotes · 0 comments
- [Security, Trust & Governance: Securing Software That Increasingly Writes Itself: SD Times 100](https://daily.dev/posts/security-trust-governance-securing-software-that-increasingly-writes-itself-sd-times-100-klafx8mu0) · SD Times · 0 upvotes · 0 comments
- [BSides San Antonio 2026: Following Trust Across Applications, Cloud, and Compliance](https://daily.dev/posts/bsides-san-antonio-2026-following-trust-across-applications-cloud-and-compliance-vb7uz7pos) · GitGuardian · 0 upvotes · 0 comments
- [SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top](https://daily.dev/posts/snowfroc-2026-secure-defaults-real-trust-and-a-better-layer-on-top-vapnkb6jq) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#ai-agents](https://daily.dev/tags/ai-agents), [#devsecops](https://daily.dev/tags/devsecops), [#appsec](https://daily.dev/tags/appsec), [#sbom](https://daily.dev/tags/sbom)

[View this post on daily.dev](https://daily.dev/posts/san-francisco-secure-software-and-appsec-summit-2026-the-next-appsec-operating-model-fcvwfzfna)
