For the last year, I’ve been watching security teams argue about AI as if it fits neatly into one of two buckets. Either it’s “just another application” and we can handle it with standard AppSec controls, or it’s some radically new category of risk that demands entirely new security theory. Having worked as both a pentester and a software engineer, I think both positions miss what’s happening.