# The beast needs a cage: What's next for AppSec post-Mythos

DevFeed: [The beast needs a cage: What's next for AppSec post-Mythos](<https://devfeed.tech/articles/the-beast-needs-a-cage-what-s-next-for-appsec-post-mythos-7738.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/the-beast-needs-a-cage-whats-next-for-appsec-post-mythos>)

Author: Dafydd Stuttard

Published: 2026-05-12T14:18:47Z

Content type: opinion

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [llms](<https://devfeed.tech/tags/llms.md>), [safety](<https://devfeed.tech/tags/safety.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

An opinion piece on how increasingly capable LLMs could automate application-security vulnerability workflows, while their nondeterminism and ability to act create safety and assurance challenges.

## Source excerpt

Now that the dust has settled on Mythos dropping, there is space for more considered reflection on the direction of travel. Mythos wasn't a surprise; it's another data point on a trajectory that's bee