Jason Haddix joins the podcast to break down how AI is transforming offensive security — from attacking LLM-powered applications to why he believes 90% of pentests will soon be done by AI. We dive into prompt injection, defending AI systems with layered controls, and how enterprises are (sometimes dangerously) adopting AI internally. We also explore the impact of AI on bug bounty programs, why “fighting AI with AI” is becoming necessary, and what the future holds for human pentesters in an increasingly automated world. Check out Jason’s company, Arcanum: https://www.arcanum-sec.com/ Arcanum: advanced offensive security training and consulting. Chapters 0:00 - Intro & Jason Haddix background 2:00 - How AI is being embedded in companies 6:00 - Prompt injection and attacking LLMs 12:00 - Defending AI systems (guardrails, classifiers, RAG) 18:00 - AI’s impact on bug bounty programs 24:00 - Will AI replace pentesters? 28:30 - The future of AI agents and security risks 37:18 - Would You Rather (security game)